CVE-2021-40839Infinite Loop in Python-rencode

CWE-835Infinite Loop5 documents4 sources
Severity
7.5HIGHNVD
EPSS
13.8%
top 5.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 10
Latest updateSep 13

Description

The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/python-rencode< python-rencode 1.0.6-2 (bookworm)

Also affects: Fedora 34, 35

Patches

🔴Vulnerability Details

3
OSV
Infinite Loop in rencode2021-09-13
GHSA
Infinite Loop in rencode2021-09-13
OSV
CVE-2021-40839: The rencode package through 12021-09-10

📋Vendor Advisories

1
Debian
CVE-2021-40839: python-rencode - The rencode package through 1.0.6 for Python allows an infinite loop in typecode...2021
CVE-2021-40839 — Infinite Loop in Debian Python-rencode | cvebase