CVE-2013-7338
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 5.05% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- python/python · apple/mac os x
- Source
- cve@mitre.org
References
- http://bugs.python.org/issue20078Exploit, Patch, Vendor Advisory
- http://hg.python.org/cpython/rev/79ea4ce431b1Exploit, Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.htmlMailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/592Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/595Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65179Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029973Third Party Advisory, VDB Entry
- https://docs.python.org/3.3/whatsnew/changelog.htmlVendor Advisory
- https://security.gentoo.org/glsa/201503-10Third Party Advisory
- https://support.apple.com/kb/HT205031Patch, Vendor Advisory
- http://bugs.python.org/issue20078Exploit, Patch, Vendor Advisory
- http://hg.python.org/cpython/rev/79ea4ce431b1Exploit, Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlMailing List
- http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.htmlMailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/592Mailing List, Third Party Advisory
- http://seclists.org/oss-sec/2014/q1/595Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65179Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1029973Third Party Advisory, VDB Entry
- https://docs.python.org/3.3/whatsnew/changelog.htmlVendor Advisory
- https://security.gentoo.org/glsa/201503-10Third Party Advisory
- https://support.apple.com/kb/HT205031Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.