CVE-2013-1752
Published: 26 December 2013
** REJECT ** Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions.
References
- http://marc.info/?l=oss-security&m=138816139322814&w=2
- http://marc.info/?l=oss-security&m=138784213903127&w=2
- http://www.openwall.com/lists/oss-security/2013/12/26
- https://ubuntu.com/security/notices/USN-2653-1
- https://www.cve.org/CVERecord?id=CVE-2013-1752
- NVD
- Launchpad
- Debian
Bugs
- https://bugzilla.redhat.com/show_bug.cgi?id=1046174
- http://bugs.python.org/issue16037
- http://bugs.python.org/issue16038
- http://bugs.python.org/issue16039
- http://bugs.python.org/issue16040
- http://bugs.python.org/issue16041
- http://bugs.python.org/issue16042
- https://bugs.launchpad.net/ubuntu/+source/python2.7/+bug/1351180