CVE-2013-1753
Published: 4 June 2015
The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.
Priority
Status
Package | Release | Status |
---|---|---|
python2.7 Launchpad, Ubuntu, Debian |
precise |
Released
(2.7.3-0ubuntu3.8)
|
trusty |
Released
(2.7.6-8ubuntu0.2)
|
|
upstream |
Released
(2.7.9-1)
|
|
utopic |
Released
(2.7.8-10ubuntu1.1)
|
|
vivid |
Not vulnerable
(2.7.9-2ubuntu3)
|
|
Patches: upstream: https://hg.python.org/cpython/rev/d50096708b2d |
||
python3.2 Launchpad, Ubuntu, Debian |
precise |
Released
(3.2.3-0ubuntu3.7)
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
Patches: upstream: https://hg.python.org/cpython/rev/a0368f81af9a |
||
python3.4 Launchpad, Ubuntu, Debian |
precise |
Does not exist
|
trusty |
Released
(3.4.0-2ubuntu1.1)
|
|
upstream |
Released
(3.4.2-4)
|
|
utopic |
Released
(3.4.2-1ubuntu0.1)
|
|
vivid |
Not vulnerable
(3.4.3-3)
|
|
Patches: upstream: https://hg.python.org/cpython/rev/6b83e21c8679 |
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.5 |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |