Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-1753

Опубликовано: 25 сент. 2012
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

It was discovered that the Python xmlrpclib did not restrict the size of a gzip compressed HTTP responses. A malicious XMLRPC server could cause an XMLRPC client using xmlrpclib to consume an excessive amount of memory.

Отчет

This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5 and 6 as their XMLRPC library did not include support for gzip encoded content.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonNot affected
Red Hat Enterprise Linux 6jythonNot affected
Red Hat Enterprise Linux 6pythonNot affected
Red Hat JBoss Enterprise Application Platform 6jython-eap6Not affected
Red Hat JBoss SOA Platform 4.3jythonNot affected
Red Hat JBoss SOA Platform 5jythonNot affected
Red Hat OpenShift Enterprise 2jythonNot affected
Red Hat Satellite 5.4jythonNot affected
Red Hat Satellite 5.5jythonNot affected
Red Hat Software Collectionspython27-pythonAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1046170python: XMLRPC library unrestricted decompression of HTTP responses using gzip enconding

EPSS

Процентиль: 68%
0.00594
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

CVSS3: 7.5
nvd
больше 5 лет назад

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

CVSS3: 7.5
debian
больше 5 лет назад

The gzip_decode function in the xmlrpc client library in Python 3.4 an ...

github
около 3 лет назад

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

suse-cvrf
почти 10 лет назад

Security update for python

EPSS

Процентиль: 68%
0.00594
Низкий

4.3 Medium

CVSS2

Уязвимость CVE-2013-1753