cbcvebase.
CVE-2021-3737
published 2022-03-04

CVE-2021-3737: A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianpypy3< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
debianpython2.7< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
debianpython3.9< pypy3 7.3.8+dfsg-1 (bookworm)pypy3 7.3.8+dfsg-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
msrccm1_python3_3.7.11-1_on_cbl_mariner_1.0
oraclecommunications_cloud_native_core_binding_support_function
oraclecommunications_cloud_native_core_network_exposure_function
oraclecommunications_cloud_native_core_policy
pythonpython
pythonpython>= 3.6.0 < 3.6.143.6.14
pythonpython>= 3.7.0 < 3.7.113.7.11
pythonpython>= 3.8.0 < 3.8.113.8.11
pythonpython>= 3.9.0 < 3.9.63.9.6
redhatcodeready_linux_builder
redhatcodeready_linux_builder_for_ibm_z_systems
redhatcodeready_linux_builder_for_power_little_endian
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.6HIGH