4.3

CVE-2013-7040

Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apple ≫ macOS X Version <= 10.10.4
Python ≫ Python Version 2.7.1
Python ≫ Python Version 2.7.1 Update rc1
Python ≫ Python Version 2.7.2 Update rc1
Python ≫ Python Version 2.7.3
Python ≫ Python Version 2.7.4
Python ≫ Python Version 2.7.5
Python ≫ Python Version 2.7.6
Python ≫ Python Version 2.7.7
Python ≫ Python Version 2.7.1150
Python ≫ Python Version 2.7.2150
Python ≫ Python Version 3.0
Python ≫ Python Version 3.0.1
Python ≫ Python Version 3.1
Python ≫ Python Version 3.1.1
Python ≫ Python Version 3.1.2
Python ≫ Python Version 3.1.3
Python ≫ Python Version 3.1.4
Python ≫ Python Version 3.1.5
Python ≫ Python Version 3.2
Python ≫ Python Version 3.2 Update alpha
Python ≫ Python Version 3.2.0
Python ≫ Python Version 3.2.1
Python ≫ Python Version 3.2.2
Python ≫ Python Version 3.2.3
Python ≫ Python Version 3.2.4
Python ≫ Python Version 3.2.5
Python ≫ Python Version 3.2.2150
Python ≫ Python Version 3.3
Python ≫ Python Version 3.3 Update beta2
Python ≫ Python Version 3.3.0
Python ≫ Python Version 3.3.1
Python ≫ Python Version 3.3.1 Update rc1
Python ≫ Python Version 3.3.2
Python ≫ Python Version 3.3.3
Python ≫ Python Version 3.3.3 Update rc1
Python ≫ Python Version 3.3.3 Update rc2
Python ≫ Python Version 3.3.4
Python ≫ Python Version 3.3.4 Update rc1
Python ≫ Python Version 3.3.5 Update -
Python ≫ Python Version 3.3.5 Update rc1
Python ≫ Python Version 3.3.5 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.26% 0.871
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
https://support.apple.com/kb/HT205031
Vendor Advisory
http://bugs.python.org/issue14621
http://www.openwall.com/lists/oss-security/2013/12/09/13
http://www.openwall.com/lists/oss-security/2013/12/09/3
http://www.securityfocus.com/bid/64194