cbcvebase.
CVE-2020-10735
published 2022-09-09

CVE-2020-10735: A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.10+dfsg-1 (bookworm)pypy3 7.3.10+dfsg-1 (bookworm)
debianpython2.7< pypy3 7.3.10+dfsg-1 (bookworm)pypy3 7.3.10+dfsg-1 (bookworm)
debianpython3.11< pypy3 7.3.10+dfsg-1 (bookworm)pypy3 7.3.10+dfsg-1 (bookworm)
debianpython3.9< pypy3 7.3.10+dfsg-1 (bookworm)pypy3 7.3.10+dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_python3_3.7.16-1_on_cbl_mariner_1.0
pythonpython
pythonpython
pythonpython>= 3.10.0 < 3.10.73.10.7
pythonpython>= 3.7.0 < 3.7.143.7.14
pythonpython>= 3.8.0 < 3.8.143.8.14
pythonpython>= 3.9.0 < 3.9.143.9.14
redhatenterprise_linux
redhatquay

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH