Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3737

Опубликовано: 09 авг. 2021
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

Отчет

Given the flaw is in the client side and it requires automatically connecting to a compromised but trusted server or manually connecting to a malicious server, the Impact of this flaw has been set to Low. It requires indeed unlikely circumstances to be exploited and when it is it is enough to stop the client or restart it. This issue did not affect the versions of rh-python38-python as shipped with Red Hat Software Collections 3 as they already contain the patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6pythonOut of support scope
Red Hat Enterprise Linux 7pythonFix deferred
Red Hat Enterprise Linux 7python3Out of support scope
Red Hat Enterprise Linux 8gimp:flatpak/python2Fix deferred
Red Hat Enterprise Linux 8inkscape:flatpak/python2Fix deferred
Red Hat Enterprise Linux 8python36:3.6/python36Affected
Red Hat Enterprise Linux 9python3.9Not affected
Red Hat Software Collectionsrh-python38-pythonNot affected
Red Hat Enterprise Linux 8python39FixedRHSA-2021:416009.11.2021
Red Hat Enterprise Linux 8python39-develFixedRHSA-2021:416009.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-835->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1995162python: urllib: HTTP client possible infinite loop on a 100 Continue response

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in python. An improperly handled HTTP response in the ...

CVSS3: 7.5
github
около 3 лет назад

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

6.5 Medium

CVSS3