4.3

CVE-2013-7040

Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.

Data is provided by the National Vulnerability Database (NVD)
ApplemacOS X Version <= 10.10.4
PythonPython Version2.7.1
PythonPython Version2.7.1 Updaterc1
PythonPython Version2.7.2 Updaterc1
PythonPython Version2.7.3
PythonPython Version2.7.4
PythonPython Version2.7.5
PythonPython Version2.7.6
PythonPython Version2.7.7
PythonPython Version2.7.1150
PythonPython Version2.7.2150
PythonPython Version3.0
PythonPython Version3.0.1
PythonPython Version3.1
PythonPython Version3.1.1
PythonPython Version3.1.2
PythonPython Version3.1.3
PythonPython Version3.1.4
PythonPython Version3.1.5
PythonPython Version3.2
PythonPython Version3.2 Updatealpha
PythonPython Version3.2.0
PythonPython Version3.2.1
PythonPython Version3.2.2
PythonPython Version3.2.3
PythonPython Version3.2.4
PythonPython Version3.2.5
PythonPython Version3.2.2150
PythonPython Version3.3
PythonPython Version3.3 Updatebeta2
PythonPython Version3.3.0
PythonPython Version3.3.1
PythonPython Version3.3.1 Updaterc1
PythonPython Version3.3.2
PythonPython Version3.3.3
PythonPython Version3.3.3 Updaterc1
PythonPython Version3.3.3 Updaterc2
PythonPython Version3.3.4
PythonPython Version3.3.4 Updaterc1
PythonPython Version3.3.5 Update-
PythonPython Version3.3.5 Updaterc1
PythonPython Version3.3.5 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.56% 0.673
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P