Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-13837

Опубликовано: 01 дек. 2025
Источник: debian

Описание

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.14fixed3.14.2-1package
python3.13fixed3.13.11-1package
python3.13no-dsatrixiepackage
python3.11removedpackage
python3.11no-dsabookwormpackage
python3.9removedpackage
pypy3unfixedpackage
pypy3no-dsatrixiepackage
pypy3no-dsabookwormpackage
pypy3postponedbullseyepackage

Примечания

  • https://github.com/python/cpython/issues/119342

  • https://github.com/python/cpython/pull/119343

  • https://github.com/python/cpython/commit/694922cf40aa3a28f898b5f5ee08b71b4922df70 (main)

  • https://github.com/python/cpython/commit/b64441e4852383645af5b435411a6f849dd1b4cb (v3.14.1)

  • https://github.com/python/cpython/commit/71fa8eb8233b37f16c88b6e3e583b461b205d1ba (v3.13.10)

  • Introduced by: https://github.com/python/cpython/commit/065266450ea5519a43bcc199e48d304f1e7038e8 (v3.4.2rc1)

Связанные уязвимости

CVSS3: 5.5
ubuntu
2 месяца назад

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

CVSS3: 5.5
nvd
2 месяца назад

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

msrc
2 месяца назад

Out-of-memory when loading Plist

CVSS3: 5.5
github
2 месяца назад

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

suse-cvrf
7 дней назад

Security update for python311