PT-2013-3377 · Python+4 · Python+4

Published

2013-12-26

·

Updated

2025-11-07

·

CVE-2013-1752

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Python versions prior to 2.6.9 Python versions prior to 2.7.4 Python versions prior to 2.7.6 Python versions prior to 3.3.3
Description The issue is related to various Python modules, including httplib, ftplib, imaplib, nntplib, poplib, and smtplib, which do not properly restrict readline calls. This allows remote attackers to cause a denial of service via a long string, resulting in memory consumption. The smtplib module is particularly affected, as it does not limit the amount of read data in its call to readline(), allowing an erroneous or malicious SMTP server to trick the module into consuming large amounts of memory.
Recommendations For Python versions prior to 2.6.9, update to version 2.6.9 or later. For Python versions prior to 2.7.4, update to version 2.7.4 or later. For Python versions prior to 2.7.6, update to version 2.7.6 or later. For Python versions prior to 3.3.3, update to version 3.3.3 or later. As a temporary workaround, consider restricting access to the vulnerable modules until a patch is available.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CESA-2015_1330
CESA-2015_2101
CVE-2013-1752
MGASA-2014-0085
MGASA-2014-0139
OPENSUSE-SU-2020:0086-1
OPENSUSE-SU-2020_0086-1
OPENSUSE-SU-2024:10536-1
OPENSUSE-SU-2024:11202-1
OPENSUSE-SU-2024:11283-1
OPENSUSE-SU-2024:11284-1
OPENSUSE-SU-2024:11285-1
OPENSUSE-SU-2024:11286-1
OPENSUSE-SU-2024:12089-1
OPENSUSE-SU-2024:12910-1
OPENSUSE-SU-2024:14109-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2025:15713-1
PSF-2019-1
RHSA-2015:1064
RHSA-2015:1330
RHSA-2015:2101
RHSA-2015_1330
RHSA-2015_2101
SUSE-SU-2014_0997-1
SUSE-SU-2014_1006-1
SUSE-SU-2014_1012-1
SUSE-SU-2015:1344-1
SUSE-SU-2015_1344-1
SUSE-SU-2020:0114-1
SUSE-SU-2020:0234-1
USN-2653-1

Affected Products

Centos
Python
Red Hat
Suse
Ubuntu