CVE-2013-7338
published 2014-04-22CVE-2013-7338: Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of…
PriorityP428high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
5.05%
91.5th percentile
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | python2.7 | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
python: malformed ZIP files could cause 100% CPU usage
vendor_redhat·2013-12-27·CVSS 7.1
CVE-2013-7338 [HIGH] python: malformed ZIP files could cause 100% CPU usage
python: malformed ZIP files could cause 100% CPU usage
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
Statement: This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Package: python (Red Hat Enterprise Linux 5) - Not affected
Package: python (Red Hat Enterprise Linux 6) - Not affected
Package: python (Red Hat Enterprise Linux 7) - Not affected
Package: python27-python (Red Hat Software Collections) - Not affected
Package: python33-python (Red Hat Software Collections) - Will not
Debian
CVE-2013-7338: python2.7 - Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (in...
vendor_debian·2013·CVSS 7.1
CVE-2013-7338 [HIGH] CVE-2013-7338: python2.7 - Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (in...
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
Scope: local
bullseye: resolved
Apple
CVE-2013-7338: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 7.1
CVE-2013-7338 [HIGH] CVE-2013-7338: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2013-7338
Component: CVE-2013-7338
GHSA
GHSA-hr8p-cf7x-v483: Python before 3
ghsa_unreviewed·2022-05-14
CVE-2013-7338 [HIGH] CWE-20 GHSA-hr8p-cf7x-v483: Python before 3
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
OSV
CVE-2013-7338: Python before 3
osv·2014-04-22·CVSS 7.1
CVE-2013-7338 [HIGH] CVE-2013-7338: Python before 3
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
No detection rules found.
No public exploits indexed.
http://bugs.python.org/issue20078http://hg.python.org/cpython/rev/79ea4ce431b1http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00008.htmlhttp://seclists.org/oss-sec/2014/q1/592http://seclists.org/oss-sec/2014/q1/595http://www.securityfocus.com/bid/65179http://www.securitytracker.com/id/1029973https://docs.python.org/3.3/whatsnew/changelog.htmlhttps://security.gentoo.org/glsa/201503-10https://support.apple.com/kb/HT205031http://bugs.python.org/issue20078http://hg.python.org/cpython/rev/79ea4ce431b1http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2014-05/msg00008.htmlhttp://seclists.org/oss-sec/2014/q1/592http://seclists.org/oss-sec/2014/q1/595http://www.securityfocus.com/bid/65179http://www.securitytracker.com/id/1029973https://docs.python.org/3.3/whatsnew/changelog.htmlhttps://security.gentoo.org/glsa/201503-10https://support.apple.com/kb/HT205031
2014-04-22
Published