Описание
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип | 
|---|---|---|---|---|
| python2.5 | removed | package | ||
| python2.6 | removed | package | ||
| python2.7 | fixed | 2.7.9-1 | package | |
| python3.1 | removed | package | ||
| python3.2 | removed | package | ||
| python3.3 | removed | package | ||
| python3.4 | fixed | 3.4.2-4 | package | |
| python3.4 | postponed | jessie | package | |
| python2.5 | no-dsa | squeeze | package | |
| python2.6 | no-dsa | squeeze | package | |
| python2.6 | no-dsa | wheezy | package | |
| python2.7 | no-dsa | wheezy | package | |
| python3.1 | no-dsa | squeeze | package | |
| python3.2 | no-dsa | wheezy | package | 
Примечания
http://bugs.python.org/issue16043
https://github.com/python/cpython/commit/eca72d47f5a639a0ac66a98a2d63b30df2ce310f (3.4)
EPSS
Связанные уязвимости
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
EPSS