VDB

DEBIAN-CVE-2020-10735

DEBIAN-CVE-2020-10735 PUBLISHED CVSS 7.5 HIGH

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:12python3.110, 0, 0
Debian:11pypy37.3.5+dfsg-2+deb11u1, 7.3.5+dfsg-2, 0
Debian:12pypy30, 0, 0
Debian:14pypy30, 0, 0
Debian:11python2.72.7.18-12, 2.7.18-13, 2.7.18-13.1
Debian:11python3.93.9.2-1, 0, *
Debian:13pypy30, 0, 0

Timeline

  • Sep 9, 2022 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›