VDB

CVE-2017-14158

CVE-2017-14158 PUBLISHED

Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separate thread to a slow storage resource, as demonstrated by interaction between dataReceived (in core/downloader/handlers/http11.py) and S3FilesStore.

EPSS 0.50% · 66.6th percentile

Risk Scores

EPSS Score
0.50%
66.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSpython-scrapy0, *, *
Ubuntu:Pro:24.04:LTSpython-scrapy*, 2.11.0-2, 2.11.1-1
Ubuntu:25.10python-scrapy0, 2.12.0-2
Ubuntu:Pro:22.04:LTSpython-scrapy0, 2.4.1-2, 2.5.1-2ubuntu0.1~esm1
Ubuntu:Pro:20.04:LTSpython-scrapy1.7.3-1ubuntu0.1~esm1, 0, 1.7.3-1
Ubuntu:16.04:LTSpython-scrapy1.0.0-1, 1.0.3-1, 0

Timeline

  • Sep 5, 2017 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Jan 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›