PT-2020-5471 · Python+10 · Python+10

Published

2020-06-17

·

Updated

2026-05-18

·

CVE-2020-14422

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Python versions prior to 3.5.10 Python versions prior to 3.6.12 Python versions prior to 3.7.9 Python versions prior to 3.8.4 Python versions prior to 3.9.0
Description The issue is related to the improper computation of hash values in the IPv4Interface and IPv6Interface classes in the Lib/ipaddress.py module of Python. This could allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and the attacker can cause many dictionary entries to be created.
Recommendations For versions prior to 3.5.10, update to version 3.5.10 or later. For versions prior to 3.6.12, update to version 3.6.12 or later. For versions prior to 3.7.9, update to version 3.7.9 or later. For versions prior to 3.8.4, update to version 3.8.4 or later. For versions prior to 3.9.0, update to version 3.9.0 or later.

Fix

DoS

Use of Insufficiently Random Values

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4641
ALT-PU-2020-2445
ALT-PU-2021-2653
ALT-PU-2024-3474
BDU:2021-00757
BIT-LIBPYTHON-2020-14422
BIT-PYTHON-2020-14422
BIT-PYTHON-MIN-2020-14422
CESA-2020_4433
CESA-2020_4641
CESA-2020_5010
CLEANSTART-2026-BM51903
CLEANSTART-2026-SY44974
CVE-2020-14422
DLA-2280-1
DLA-3424-1
MGASA-2020-0343
MGASA-2020-0451
OESA-2022-1944
OESA-2022-1945
OPENSUSE-SU-2020:0931-1
OPENSUSE-SU-2020:0940-1
OPENSUSE-SU-2020:0989-1
OPENSUSE-SU-2020:1002-1
OPENSUSE-SU-2020:2332-1
OPENSUSE-SU-2020:2333-1
OPENSUSE-SU-2020_0931-1
OPENSUSE-SU-2020_0940-1
OPENSUSE-SU-2020_0989-1
OPENSUSE-SU-2020_1002-1
OPENSUSE-SU-2020_2332-1
OPENSUSE-SU-2020_2333-1
OPENSUSE-SU-2024:11284-1
PSF-2020-3
RHSA-2020:4285
RHSA-2020:4299
RHSA-2020:4433
RHSA-2020:4641
RHSA-2020:5010
RHSA-2020_4433
RHSA-2020_4641
RHSA-2020_5010
RLSA-2020:4641
ROSA-SA-2023-2202
SUSE-SU-2020:1822-1
SUSE-SU-2020:1920-1
SUSE-SU-2020:1939-1
SUSE-SU-2020:1940-1
SUSE-SU-2020:2157-1
SUSE-SU-2020:2216-1
SUSE-SU-2020:2699-1
SUSE-SU-2020:3563-1
SUSE-SU-2020:3930-1
SUSE-SU-2020_1822-1
SUSE-SU-2020_1920-1
SUSE-SU-2020_2157-1
USN-4428-1
USN-6891-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Python
Red Hat
Rocky Linux
Suse
Ubuntu