Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1752

Опубликовано: 25 сент. 2012
Источник: redhat
CVSS2: 4.3

Описание

It was discovered that multiple Python standard library modules implementing network protocols (such as httplib or smtplib) failed to restrict sizes of server responses. A malicious server could cause a client using one of the affected modules to consume an excessive amount of memory.

Отчет

Red Hat JBoss SOA Platform 5 is now in Maintenance Support phase receiving only qualified Important and Critical impact security fixes; and Red Hat JBoss SOA Platform 4.3 is now in Extended Life Support phase receiving only Critical impact security fixes. This issue has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware Product Life Cycle: https://access.redhat.com/support/policy/updates/jboss_notes/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonWill not fix
Red Hat Enterprise Linux 5redhat-support-lib-pythonWill not fix
Red Hat Enterprise Linux 6jythonWill not fix
Red Hat Enterprise Linux 6redhat-support-lib-pythonWill not fix
Red Hat Enterprise Linux 7redhat-support-lib-pythonWill not fix
Red Hat JBoss Enterprise Application Platform 6jython-eap6Not affected
Red Hat JBoss SOA Platform 4.3jythonWill not fix
Red Hat JBoss SOA Platform 5jythonWill not fix
Red Hat OpenShift Enterprise 2jythonWill not fix
Red Hat Satellite 5.4jythonWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1046174python: multiple unbound readline() DoS flaws in python stdlib

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 6 лет назад

Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions

nvd
больше 6 лет назад

Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions

suse-cvrf
больше 10 лет назад

Security update for python

oracle-oval
больше 10 лет назад

ELSA-2015-1330: python security, bug fix, and enhancement update (MODERATE)

oracle-oval
около 10 лет назад

ELSA-2015-2101: python security, bug fix, and enhancement update (MODERATE)

4.3 Medium

CVSS2