Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-7592

Опубликовано: 19 авг. 2024
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 7.5

Описание

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

РелизСтатусПримечание
devel

DNE

esm-apps/focal

released

2.7.18-1~20.04.4+esm2
esm-apps/jammy

released

2.7.18-13ubuntu1.2+esm2
esm-infra-legacy/trusty

not-affected

2.7.6-8ubuntu0.6+esm20
esm-infra/bionic

released

2.7.17-1~18.04ubuntu1.13+esm5
esm-infra/xenial

released

2.7.12-1ubuntu0~16.04.18+esm10
focal

ignored

end of standard support, was needed
jammy

needed

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

released

3.10.12-1~22.04.6
noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

needs-triage

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

released

3.12.3-1ubuntu0.2
oracular

not-affected

3.12.6-1
plucky

DNE

upstream

released

3.12.6-1

Показывать по

РелизСтатусПримечание
devel

not-affected

3.13.0~rc2-1
esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

not-affected

3.13.0~rc2-1
plucky

not-affected

3.13.0~rc2-1
upstream

released

3.13.0~rc2-1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

trusty/esm

ignored

end of ESM support, was needs-triage
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

not-affected

3.5.2-2ubuntu0~16.04.4~14.04.1+esm3
esm-infra/focal

DNE

esm-infra/xenial

released

3.5.2-2ubuntu0~16.04.13+esm14
focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

trusty/esm

released

3.5.2-2ubuntu0~16.04.4~14.04.1+esm3

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/bionic

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-infra/focal

not-affected

3.8.10-0ubuntu1~20.04.12
focal

released

3.8.10-0ubuntu1~20.04.12
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/focal

needs-triage

focal

ignored

end of standard support, was needs-triage
jammy

DNE

noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 55%
0.00325
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
10 месяцев назад

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

CVSS3: 7.5
nvd
10 месяцев назад

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

CVSS3: 7.5
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
10 месяцев назад

There is a LOW severity vulnerability affecting CPython, specifically ...

CVSS3: 7.5
redos
8 месяцев назад

Уязвимость python3.12

EPSS

Процентиль: 55%
0.00325
Низкий

7.5 High

CVSS3

Уязвимость CVE-2024-7592