CVE-2012-0845Infinite Loop in Python

CWE-39919 documents7 sources
Severity
5.0MEDIUMNVD
EPSS
2.8%
top 13.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 5
Latest updateMay 13

Description

SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the Content-Length header.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

debiandebian/python2.7< python2.7 2.7.3~rc1-1 (bullseye)
NVDpython/python2.6.7+55

Patches

🔴Vulnerability Details

2
GHSA
GHSA-68xj-hf27-5jvq: SimpleXMLRPCServer2022-05-13
OSV
CVE-2012-0845: SimpleXMLRPCServer2012-10-05

📋Vendor Advisories

8
Ubuntu
Python 3.1 vulnerabilities2012-10-24
Ubuntu
Python 3.2 vulnerabilities2012-10-23
Ubuntu
Python 2.5 vulnerabilities2012-10-17
Ubuntu
Python 2.4 vulnerabilities2012-10-17
Ubuntu
Python 2.6 vulnerabilities2012-10-04

💬Community

8
Bugzilla
CVE-2012-0845 pypy: SimpleXMLRPCServer CPU usage DoS via malformed XML-RPC request [fedora-all]2012-03-30
Bugzilla
CVE-2011-4940 CVE-2012-0845 CVE-2011-4944 python3 various flaws [fedora-all]2012-03-30
Bugzilla
CVE-2011-4940 CVE-2012-0845 CVE-2011-4944 python various flaws [fedora-all]2012-03-30
Bugzilla
CVE-2012-0845 python26: SimpleXMLRPCServer DoS (excessive CPU usage) via malformed XML-RPC / HTTP POST request [epel-5]2012-02-14
Bugzilla
CVE-2012-0845 python3: SimpleXMLRPCServer DoS (excessive CPU usage) via malformed XML-RPC / HTTP POST request [fedora-all]2012-02-14