CVE-2013-1752 Affecting python2.7 package, versions <2.7.9-1


low

Snyk CVSS

      Threat Intelligence

      EPSS 0.24% (62nd percentile)
    Expand this section
    SUSE
    5.3 medium
    Expand this section
    Red Hat
    4.3 medium

    Do your applications use this vulnerable package?

    In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

    Test your applications
    • Snyk ID SNYK-DEBIAN8-PYTHON27-306598
    • published 27 Jun 2018
    • disclosed 3 Jun 2019

    How to fix?

    Upgrade Debian:8 python2.7 to version 2.7.9-1 or higher.

    NVD Description

    Note: Versions mentioned in the description apply only to the upstream python2.7 package and not the python2.7 package as distributed by Debian. See How to fix? for Debian:8 relevant fixed versions and status.

    Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions