<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">CVE-2014-9365</DocumentTitle>
  <DocumentType>SUSE CVE</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE CVE-2014-9365</ID>
    </Identification>
    <Status>Interim</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>18</Number>
        <Date>2025-11-05T05:00:31Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-05-30T13:24:39Z</InitialReleaseDate>
    <CurrentReleaseDate>2025-11-05T05:00:31Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf-cve.pl</Engine>
      <Date>2020-12-27T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="CVE" Type="Summary" Ordinal="1" xml:lang="en">CVE-2014-9365</Note>
    <Note Title="Mitre CVE Description" Type="Description" Ordinal="2" xml:lang="en">The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="4" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="Magnum Orchestration 7">
      <Branch Type="Product Name" Name="Magnum Orchestration 7">
        <FullProductName ProductID="Magnum Orchestration 7" CPE="cpe:/o:suse:openstack-cloud-magnum-orchestration:7">Magnum Orchestration 7</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Container as a Service Platform 2.0">
      <Branch Type="Product Name" Name="SUSE Container as a Service Platform 2.0">
        <FullProductName ProductID="SUSE Container as a Service Platform 2.0" CPE="cpe:/o:suse:caasp:2.0">SUSE Container as a Service Platform 2.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 3">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 3">
        <FullProductName ProductID="SUSE Enterprise Storage 3" CPE="cpe:/o:suse:ses:3">SUSE Enterprise Storage 3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 4">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 4">
        <FullProductName ProductID="SUSE Enterprise Storage 4" CPE="cpe:/o:suse:ses:4">SUSE Enterprise Storage 4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Enterprise Storage 5">
      <Branch Type="Product Name" Name="SUSE Enterprise Storage 5">
        <FullProductName ProductID="SUSE Enterprise Storage 5" CPE="cpe:/o:suse:ses:5">SUSE Enterprise Storage 5</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Liberty Linux 7">
      <Branch Type="Product Name" Name="SUSE Liberty Linux 7">
        <FullProductName ProductID="SUSE Liberty Linux 7" CPE="cpe:/o:suse:sll:7">SUSE Liberty Linux 7</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Desktop 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Desktop 12 SP3">
        <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP3" CPE="cpe:/o:suse:sled:12:sp3">SUSE Linux Enterprise Desktop 12 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP3">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP4">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 12 SP5">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Advanced Systems Management 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12" CPE="cpe:/o:suse:sle-module-adv-systems-management:12">SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Containers 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12" CPE="cpe:/o:suse:sle-module-containers:12">SUSE Linux Enterprise Module for Containers 12</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Public Cloud 12">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12" CPE="cpe:/o:suse:sle-module-public-cloud:12">SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Client Tools for SLE 12">
      <Branch Type="Product Name" Name="SUSE Manager Client Tools for SLE 12">
        <FullProductName ProductID="SUSE Manager Client Tools for SLE 12" CPE="cpe:/o:suse:sle-manager-tools:12">SUSE Manager Client Tools for SLE 12</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy 3.0">
      <Branch Type="Product Name" Name="SUSE Manager Proxy 3.0">
        <FullProductName ProductID="SUSE Manager Proxy 3.0" CPE="cpe:/o:suse:suse-manager-proxy:3.0">SUSE Manager Proxy 3.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Proxy 3.1">
      <Branch Type="Product Name" Name="SUSE Manager Proxy 3.1">
        <FullProductName ProductID="SUSE Manager Proxy 3.1" CPE="cpe:/o:suse:suse-manager-proxy:3.1">SUSE Manager Proxy 3.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 3.0">
      <Branch Type="Product Name" Name="SUSE Manager Server 3.0">
        <FullProductName ProductID="SUSE Manager Server 3.0" CPE="cpe:/o:suse:suse-manager-server:3.0">SUSE Manager Server 3.0</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Manager Server 3.1">
      <Branch Type="Product Name" Name="SUSE Manager Server 3.1">
        <FullProductName ProductID="SUSE Manager Server 3.1" CPE="cpe:/o:suse:suse-manager-server:3.1">SUSE Manager Server 3.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 6">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 6">
        <FullProductName ProductID="SUSE OpenStack Cloud 6" CPE="cpe:/o:suse:suse-openstack-cloud:6">SUSE OpenStack Cloud 6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE OpenStack Cloud 7">
      <Branch Type="Product Name" Name="SUSE OpenStack Cloud 7">
        <FullProductName ProductID="SUSE OpenStack Cloud 7" CPE="cpe:/o:suse:suse-openstack-cloud:7">SUSE OpenStack Cloud 7</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="python-2.7.5-58.el7">
      <FullProductName ProductID="python-2.7.5-58.el7" CPE="cpe:2.3:a:python_software_foundation:cpython:2.7.5:*:*:*:*:*:*:*">python-2.7.5-58.el7</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-backports.ssl_match_hostname">
      <FullProductName ProductID="python-backports.ssl_match_hostname">python-backports.ssl_match_hostname</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-debug-2.7.5-58.el7">
      <FullProductName ProductID="python-debug-2.7.5-58.el7">python-debug-2.7.5-58.el7</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-devel-2.7.5-58.el7">
      <FullProductName ProductID="python-devel-2.7.5-58.el7">python-devel-2.7.5-58.el7</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-libs-2.7.5-58.el7">
      <FullProductName ProductID="python-libs-2.7.5-58.el7">python-libs-2.7.5-58.el7</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-test-2.7.5-58.el7">
      <FullProductName ProductID="python-test-2.7.5-58.el7">python-test-2.7.5-58.el7</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-tools-2.7.5-58.el7">
      <FullProductName ProductID="python-tools-2.7.5-58.el7">python-tools-2.7.5-58.el7</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="tkinter-2.7.5-58.el7">
      <FullProductName ProductID="tkinter-2.7.5-58.el7">tkinter-2.7.5-58.el7</FullProductName>
    </Branch>
    <Relationship ProductReference="python-2.7.5-58.el7" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 7">
      <FullProductName ProductID="SUSE Liberty Linux 7:python-2.7.5-58.el7">python-2.7.5-58.el7 as a component of SUSE Liberty Linux 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-debug-2.7.5-58.el7" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 7">
      <FullProductName ProductID="SUSE Liberty Linux 7:python-debug-2.7.5-58.el7">python-debug-2.7.5-58.el7 as a component of SUSE Liberty Linux 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-devel-2.7.5-58.el7" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 7">
      <FullProductName ProductID="SUSE Liberty Linux 7:python-devel-2.7.5-58.el7">python-devel-2.7.5-58.el7 as a component of SUSE Liberty Linux 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-libs-2.7.5-58.el7" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 7">
      <FullProductName ProductID="SUSE Liberty Linux 7:python-libs-2.7.5-58.el7">python-libs-2.7.5-58.el7 as a component of SUSE Liberty Linux 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-test-2.7.5-58.el7" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 7">
      <FullProductName ProductID="SUSE Liberty Linux 7:python-test-2.7.5-58.el7">python-test-2.7.5-58.el7 as a component of SUSE Liberty Linux 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-tools-2.7.5-58.el7" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 7">
      <FullProductName ProductID="SUSE Liberty Linux 7:python-tools-2.7.5-58.el7">python-tools-2.7.5-58.el7 as a component of SUSE Liberty Linux 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="tkinter-2.7.5-58.el7" RelationType="Default Component Of" RelatesToProductReference="SUSE Liberty Linux 7">
      <FullProductName ProductID="SUSE Liberty Linux 7:tkinter-2.7.5-58.el7">tkinter-2.7.5-58.el7 as a component of SUSE Liberty Linux 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="Magnum Orchestration 7">
      <FullProductName ProductID="Magnum Orchestration 7:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of Magnum Orchestration 7</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Container as a Service Platform 2.0">
      <FullProductName ProductID="SUSE Container as a Service Platform 2.0:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Container as a Service Platform 2.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 3">
      <FullProductName ProductID="SUSE Enterprise Storage 3:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Enterprise Storage 3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 4">
      <FullProductName ProductID="SUSE Enterprise Storage 4:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Enterprise Storage 4</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Enterprise Storage 5">
      <FullProductName ProductID="SUSE Enterprise Storage 5:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Enterprise Storage 5</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Desktop 12 SP3">
      <FullProductName ProductID="SUSE Linux Enterprise Desktop 12 SP3:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Linux Enterprise Desktop 12 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Advanced Systems Management 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Advanced Systems Management 12:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Linux Enterprise Module for Advanced Systems Management 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Containers 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Containers 12:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Linux Enterprise Module for Containers 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Public Cloud 12">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Public Cloud 12:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Linux Enterprise Module for Public Cloud 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Client Tools for SLE 12">
      <FullProductName ProductID="SUSE Manager Client Tools for SLE 12:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Manager Client Tools for SLE 12</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.0">
      <FullProductName ProductID="SUSE Manager Proxy 3.0:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Manager Proxy 3.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Proxy 3.1">
      <FullProductName ProductID="SUSE Manager Proxy 3.1:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Manager Proxy 3.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.0">
      <FullProductName ProductID="SUSE Manager Server 3.0:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Manager Server 3.0</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE Manager Server 3.1">
      <FullProductName ProductID="SUSE Manager Server 3.1:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE Manager Server 3.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 6">
      <FullProductName ProductID="SUSE OpenStack Cloud 6:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE OpenStack Cloud 6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-backports.ssl_match_hostname" RelationType="Default Component Of" RelatesToProductReference="SUSE OpenStack Cloud 7">
      <FullProductName ProductID="SUSE OpenStack Cloud 7:python-backports.ssl_match_hostname">python-backports.ssl_match_hostname as a component of SUSE OpenStack Cloud 7</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4) xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x before 3.4.3, when accessing an HTTPS URL, do not (a) check the certificate against a trust store or verify that the server hostname matches a domain name in the subject's (b) Common Name or (c) subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.</Note>
    </Notes>
    <CVE>CVE-2014-9365</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Liberty Linux 7:python-2.7.5-58.el7</ProductID>
        <ProductID>SUSE Liberty Linux 7:python-debug-2.7.5-58.el7</ProductID>
        <ProductID>SUSE Liberty Linux 7:python-devel-2.7.5-58.el7</ProductID>
        <ProductID>SUSE Liberty Linux 7:python-libs-2.7.5-58.el7</ProductID>
        <ProductID>SUSE Liberty Linux 7:python-test-2.7.5-58.el7</ProductID>
        <ProductID>SUSE Liberty Linux 7:python-tools-2.7.5-58.el7</ProductID>
        <ProductID>SUSE Liberty Linux 7:tkinter-2.7.5-58.el7</ProductID>
      </Status>
      <Status Type="Known Not Affected">
        <ProductID>Magnum Orchestration 7:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Container as a Service Platform 2.0:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Enterprise Storage 3:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Enterprise Storage 4:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Enterprise Storage 5:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Linux Enterprise Desktop 12 SP3:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Advanced Systems Management 12:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Containers 12:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Public Cloud 12:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Manager Client Tools for SLE 12:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Manager Proxy 3.0:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Manager Proxy 3.1:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Manager Server 3.0:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE Manager Server 3.1:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE OpenStack Cloud 6:python-backports.ssl_match_hostname</ProductID>
        <ProductID>SUSE OpenStack Cloud 7:python-backports.ssl_match_hostname</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5.8</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:P/I:P/A:N</VectorV2>
      </ScoreSetV2>
    </CVSSScoreSets>
  </Vulnerability>
</cvrfdoc>
