[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2022-45061Date: (C)2022-11-11   (M)2024-04-19


An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.5CVSS Score :
Exploit Score: 3.9Exploit Score:
Impact Score: 3.6Impact Score:
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: NETWORKAccess Vector:
Attack Complexity: LOWAccess Complexity:
Privileges Required: NONEAuthentication:
User Interaction: NONEConfidentiality:
Scope: UNCHANGEDIntegrity:
Confidentiality: NONEAvailability:
Integrity: NONE 
Availability: HIGH 
  
Reference:
FEDORA-2022-18b234c18b
FEDORA-2022-3d7e44dbd5
FEDORA-2022-3e859b6bc6
FEDORA-2022-45d2cfdfa4
FEDORA-2022-50deb53896
FEDORA-2022-6b8b96f883
FEDORA-2022-6ba889e0e3
FEDORA-2022-6d51289820
FEDORA-2022-6f4e6120d7
FEDORA-2022-93c6916349
FEDORA-2022-b2f06fbb62
FEDORA-2022-bcf089dd07
FEDORA-2022-dbb811d203
FEDORA-2022-de755fd092
FEDORA-2022-e1ce71ff40
FEDORA-2022-e699dd5247
FEDORA-2022-e6d0495206
FEDORA-2022-fbf6a320fe
FEDORA-2022-fd3771db30
FEDORA-2022-fdb2739feb
FEDORA-2023-097dd40685
FEDORA-2023-129178fd27
FEDORA-2023-5460cf6dfb
FEDORA-2023-78b4ce2f23
FEDORA-2023-943556a733
FEDORA-2023-a990c93ed0
FEDORA-2023-af5206f71d
FEDORA-2023-c43a940a93
FEDORA-2023-f1381c83af
GLSA-202305-02
https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
https://github.com/python/cpython/issues/98433
https://security.netapp.com/advisory/ntap-20221209-0007/

CPE    1
cpe:/a:python:python
CWE    1
CWE-407
OVAL    72
oval:org.secpod.oval:def:3300962
oval:org.secpod.oval:def:5800149
oval:org.secpod.oval:def:124739
oval:org.secpod.oval:def:126118
...

© SecPod Technologies