7.1

CVE-2013-7338

Exploit
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version 3.3.0 Update -
Python ≫ Python Version 3.3.0 Update alpha1
Python ≫ Python Version 3.3.0 Update alpha2
Python ≫ Python Version 3.3.0 Update alpha3
Python ≫ Python Version 3.3.0 Update alpha4
Python ≫ Python Version 3.3.0 Update beta1
Python ≫ Python Version 3.3.0 Update beta2
Python ≫ Python Version 3.3.0 Update rc1
Python ≫ Python Version 3.3.0 Update rc2
Python ≫ Python Version 3.3.0 Update rc3
Python ≫ Python Version 3.3.1 Update -
Python ≫ Python Version 3.3.1 Update rc1
Python ≫ Python Version 3.3.2
Python ≫ Python Version 3.3.3
Python ≫ Python Version 3.3.3 Update rc1
Python ≫ Python Version 3.3.3 Update rc2
Apple ≫ macOS X Version <= 10.10.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.06% 0.912
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Mailing List
https://support.apple.com/kb/HT205031
Patch
Vendor Advisory
http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/201503-10
Third Party Advisory
http://bugs.python.org/issue20078
Patch
Vendor Advisory
Exploit
http://hg.python.org/cpython/rev/79ea4ce431b1
Patch
Vendor Advisory
Exploit
http://seclists.org/oss-sec/2014/q1/592
Third Party Advisory
Mailing List
http://seclists.org/oss-sec/2014/q1/595
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/65179
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1029973
Third Party Advisory
VDB Entry
https://docs.python.org/3.3/whatsnew/changelog.html
Vendor Advisory