Уязвимость бесконечного цикла в HTTP-клиенте Python из-за некорректной обработки HTTP-ответа
Описание
В Python обнаружена уязвимость в коде HTTP-клиента. Некорректная обработка HTTP-ответа может позволить удалённому злоумышленнику, контролирующему HTTP-сервер, заставить клиентский скрипт войти в бесконечный цикл, потребляя ресурсы процессора. Основная угроза этой уязвимости связана с нарушением доступности системы.
Тип уязвимости
- Бесконечный цикл (infinite loop)
- Нарушение доступности системы
Ссылки
- ExploitIssue TrackingVendor Advisory
- Issue TrackingPatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- ExploitIssue TrackingVendor Advisory
- Issue TrackingPatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
Одно из
Одно из
EPSS
7.5 High
CVSS3
7.1 High
CVSS2
Дефекты
Связанные уязвимости
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
A flaw was found in python. An improperly handled HTTP response in the ...
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
EPSS
7.5 High
CVSS3
7.1 High
CVSS2