CVE-2020-7212
published 2020-03-06CVE-2020-7212: The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.37%
87.5th percentile
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | python-urllib3 | < python-urllib3 1.25.8-1 (bookworm) | python-urllib3 1.25.8-1 (bookworm) |
| python | urllib3 | 1.25.2 – 1.25.7 | — |
| urllib3 | urllib3 | >= 1.25.2 < 1.25.8 | 1.25.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_redhat7.8HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Uncontrolled Resource Consumption in urllib3
osv·2021-04-30
CVE-2020-7212 [HIGH] Uncontrolled Resource Consumption in urllib3
Uncontrolled Resource Consumption in urllib3
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
GHSA
Uncontrolled Resource Consumption in urllib3
ghsa·2021-04-30
CVE-2020-7212 [HIGH] CWE-400 Uncontrolled Resource Consumption in urllib3
Uncontrolled Resource Consumption in urllib3
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
OSV
CVE-2020-7212: The _encode_invalid_chars function in util/url
osv·2020-03-06·CVSS 7.5
CVE-2020-7212 [HIGH] CVE-2020-7212: The _encode_invalid_chars function in util/url
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
Red Hat
kernel: Improper input validation in some Intel(R) Graphics Drivers
vendor_redhat·2021-02-17·CVSS 5.5
CVE-2020-12363 [MEDIUM] CWE-20 kernel: Improper input validation in some Intel(R) Graphics Drivers
kernel: Improper input validation in some Intel(R) Graphics Drivers
Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.
A flaw was found in the Linux kernel. Improper input validation in some Intel(R) Graphics Drivers may allow a privileged user to potentially enable a denial of service via local access.
Statement: To fix this issue a combination of linux-firmware and kernel update is required to be installed on the system.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicab
Red Hat
kernel: Integer overflow in Intel(R) Graphics Drivers
vendor_redhat·2021-02-17·CVSS 7.8
CVE-2020-12362 [HIGH] CWE-190 kernel: Integer overflow in Intel(R) Graphics Drivers
kernel: Integer overflow in Intel(R) Graphics Drivers
Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.
A flaw was found in the Linux kernel. An integer overflow in the firmware for some Intel(R) Graphics Drivers may allow a privileged user to potentially enable an escalation of privilege via local access. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Statement: Only users that specify i915.enable_guc=-1 or i915.enable_guc=1 or 2 are open to be exploited by this issue.
Due to the full fix (combination of kernel and firmware upda
Red Hat
kernel: Null pointer dereference in some Intel(R) Graphics Drivers
vendor_redhat·2021-02-17·CVSS 5.5
CVE-2020-12364 [MEDIUM] CWE-476 kernel: Null pointer dereference in some Intel(R) Graphics Drivers
kernel: Null pointer dereference in some Intel(R) Graphics Drivers
Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.
Null pointer reference in some Intel(R) Graphics Drivers for Microsoft Windows and the Linux kernel may allow a privileged user to potentially enable a denial of service via local access.
Statement: To fix this issue a combination of linux-firmware and kernel update is required to be installed on the system.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, ap
Red Hat
python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py
vendor_redhat·2020-03-06·CVSS 7.5
CVE-2020-7212 [HIGH] CWE-400 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py
python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
If provided a specially crafted URL, urllib3 could be made to encod
Debian
CVE-2020-7212: python-urllib3 - The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 ...
vendor_debian·2020·CVSS 7.5
CVE-2020-7212 [HIGH] CVE-2020-7212: python-urllib3 - The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 ...
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
Scope: local
bookworm: resolved (fixed in 1.25.8-1)
bullseye: resolved (fixed in 1.25.8-1)
forky: resolved (fixed in 1.25.8-1)
sid: resolved (fixed in 1.25.8-1)
trixie: resolved (fixed in
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-7212 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py [fedora-all]
bugzilla·2020-03-10·CVSS 7.5
CVE-2020-7212 [HIGH] CVE-2020-7212 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py [fedora-all]
CVE-2020-7212 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg co
Bugzilla
CVE-2020-7212 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py
bugzilla·2020-03-10·CVSS 7.5
CVE-2020-7212 [HIGH] CVE-2020-7212 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py
CVE-2020-7212 python-urllib3: inefficient algorithm allows a DoS (CPU consumption) in _encode_invalid_chars function in util/url.py
The _encode_invalid_chars function in util/url.py in the urllib3 library 1.25.2 through 1.25.7 for Python allows a denial of service (CPU consumption) because of an inefficient algorithm. The percent_encodings array contains all matches of percent encodings. It is not deduplicated. For a URL of length N, the size of percent_encodings may be up to O(N). The next step (normalize existing percent-encoded bytes) also takes up to O(N) for each step, so the total time is O(N^2). If percent_encodings were deduplicated, the time to compute _encode_invalid_chars would be O(kN), where k is at most 484 ((10+6*2)^2).
Reference and upstream commit:
https://github.com/url
https://github.com/urllib3/urllib3/blob/master/CHANGES.rsthttps://github.com/urllib3/urllib3/commit/a74c9cfbaed9f811e7563cfc3dce894928e0221ahttps://pypi.org/project/urllib3/1.25.8/https://github.com/urllib3/urllib3/blob/master/CHANGES.rsthttps://github.com/urllib3/urllib3/commit/a74c9cfbaed9f811e7563cfc3dce894928e0221ahttps://pypi.org/project/urllib3/1.25.8/
2020-03-06
Published