PT-2013-3377 · Python+4 · Python+4

Publicado

2013-12-26

·

Atualizado

2025-11-07

·

CVE-2013-1752

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Name of the Vulnerable Software and Affected Versions Python versions prior to 2.6.9 Python versions prior to 2.7.4 Python versions prior to 2.7.6 Python versions prior to 3.3.3
Description The issue is related to various Python modules, including httplib, ftplib, imaplib, nntplib, poplib, and smtplib, which do not properly restrict readline calls. This allows remote attackers to cause a denial of service via a long string, resulting in memory consumption. The smtplib module is particularly affected, as it does not limit the amount of read data in its call to readline(), allowing an erroneous or malicious SMTP server to trick the module into consuming large amounts of memory.
Recommendations For Python versions prior to 2.6.9, update to version 2.6.9 or later. For Python versions prior to 2.7.4, update to version 2.7.4 or later. For Python versions prior to 2.7.6, update to version 2.7.6 or later. For Python versions prior to 3.3.3, update to version 3.3.3 or later. As a temporary workaround, consider restricting access to the vulnerable modules until a patch is available.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CESA-2015_1330
CESA-2015_2101
CVE-2013-1752
MGASA-2014-0085
MGASA-2014-0139
OPENSUSE-SU-2020:0086-1
OPENSUSE-SU-2020_0086-1
OPENSUSE-SU-2024:10536-1
OPENSUSE-SU-2024:11202-1
OPENSUSE-SU-2024:11283-1
OPENSUSE-SU-2024:11284-1
OPENSUSE-SU-2024:11285-1
OPENSUSE-SU-2024:11286-1
OPENSUSE-SU-2024:12089-1
OPENSUSE-SU-2024:12910-1
OPENSUSE-SU-2024:14109-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2025:15713-1
PSF-2019-1
RHSA-2015:1064
RHSA-2015:1330
RHSA-2015:2101
RHSA-2015_1330
RHSA-2015_2101
SUSE-SU-2014_0997-1
SUSE-SU-2014_1006-1
SUSE-SU-2014_1012-1
SUSE-SU-2015:1344-1
SUSE-SU-2015_1344-1
SUSE-SU-2020:0114-1
SUSE-SU-2020:0234-1
USN-2653-1

Produtos afetados

Centos
Python
Red Hat
Suse
Ubuntu