Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-40839

Опубликовано: 10 сент. 2021
Источник: debian

Описание

The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-rencodefixed1.0.6-2package
python-rencodeno-dsabullseyepackage
python-rencodeno-dsabusterpackage
python-rencodeno-dsastretchpackage

Примечания

  • https://github.com/aresch/rencode/commit/572ff74586d9b1daab904c6f7f7009ce0143bb75

  • https://github.com/aresch/rencode/pull/29

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

CVSS3: 7.5
nvd
больше 4 лет назад

The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

CVSS3: 7.5
github
больше 4 лет назад

Infinite Loop in rencode