CVE-2013-7338 REJECTED

Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.

EPSS 5.92% · 90.5th percentile

Risk Scores

EPSS Score
5.92%
90.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSpython3.40, 3.4~b1-0ubuntu3, 3.4~b1-4ubuntu4

Timeline

References

Open in Interactive Console →