« Volver al listado

CVE-2013-7338

Estado: ModificadaAlta (7.1)—

Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-7338",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-04-22T14:23:34.893",
  "references": [
    {
      "url": "http://bugs.python.org/issue20078",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://hg.python.org/cpython/rev/79ea4ce431b1",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html",
      "tags": [
        "Mailing List"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/oss-sec/2014/q1/592",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/oss-sec/2014/q1/595",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/65179",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id/1029973",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://docs.python.org/3.3/whatsnew/changelog.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.gentoo.org/glsa/201503-10",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.apple.com/kb/HT205031",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.python.org/issue20078",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://hg.python.org/cpython/rev/79ea4ce431b1",
      "tags": [
        "Exploit",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html",
      "tags": [
        "Mailing List"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/oss-sec/2014/q1/592",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/oss-sec/2014/q1/595",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/65179",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1029973",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.python.org/3.3/whatsnew/changelog.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201503-10",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.apple.com/kb/HT205031",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function."
    },
    {
      "lang": "es",
      "value": "Python anterior a 3.3.4 RC1 permite a atacantes remotos causar una denegación de servicio (bucle infinito y consumo de CPU) a través de un valor de tamaño de archivo más grande que el tamaño del archivo zip hacia la función (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract o (5) ZipFile.extractall."
    }
  ],
  "lastModified": "2026-06-17T00:01:47.027",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8F5D6EE-7E52-4E82-AFA3-056E2CCA6A95"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F699D1AE-6297-4F3E-B276-7DC246CAACA7"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19C43276-7B2C-4E74-BB71-671934F5BB64"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "873A7118-EEFD-49CC-B778-6E91942C6FC2"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F96A8F58-C28D-4EB2-A3D5-276D17E8E0DE"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2ACF1669-4D46-4D44-972C-A2D5E5D51069"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7FF3E0E-3D41-47D0-AE18-ADB2EC2942BE"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F358C4D2-7A49-4092-BB17-9423E5381F44"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D17DA663-B755-4D41-A151-347036187E92"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A837C0BC-C3C8-47B8-8BEA-8F01F4B1A35B"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.1:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3FC85C4C-B721-4BD9-BFFD-DCEC32A77FB9"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D553F40-92C2-4537-AF74-5F9307E20AE4"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "121225D0-C5DA-4F26-93B8-3D56BC1D38B1"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52DD66F7-FE7B-4C1C-B07B-F9E4CEEA7AFD"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.3:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5D540913-0EEF-413B-8AFD-82E858844FD6"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.3:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFD75566-C783-4B16-9FF1-4AC2670310F2"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7883E465-932D-4C11-AA54-97E44181F906",
              "versionEndIncluding": "10.10.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}