CVE-2024-4032

Updated: 2025-08-20 02:31:27.584079

Description:

The “ipaddress” module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as “globally reachable” or “private”. This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn’t be returned in accordance with the latest information from the IANA Special-Purpose Address Registries. CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x LOW 3.7

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CloudLinux 6 ELS python 2.6.6 3.7 LOW Ignored 2024-08-29 12:10:11 Ignored due to low severity
CloudLinux 7 ELS python 2.7.5 3.7 LOW Ignored 2024-08-29 05:23:12 Ignored due to low severity
CloudLinux 7 ELS python3 3.6.8 3.7 LOW Ignored 2024-07-24 05:16:54 Ignored due to low severity
Oracle Linux 6 ELS python 2.6.6 3.7 LOW Ignored 2024-08-29 12:10:11 Ignored due to low severity
Ubuntu 16.04 ELS python3.5 3.5.2 3.7 LOW Released CLSA-2025:1742379028 2025-03-20 03:52:36
Total: 15