CVE-2013-1753

Published: 04 June 2015

The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
python2.7
Launchpad, Ubuntu, Debian
Upstream
Released (2.7.9-1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.7.6-8ubuntu0.2)
Patches:
Upstream: https://hg.python.org/cpython/rev/d50096708b2d
python3.2
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

Patches:
Upstream: https://hg.python.org/cpython/rev/a0368f81af9a
python3.4
Launchpad, Ubuntu, Debian
Upstream
Released (3.4.2-4)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (3.4.0-2ubuntu1.1)
Patches:
Upstream: https://hg.python.org/cpython/rev/6b83e21c8679