Lucene search

K
cve[email protected]CVE-2013-7040
HistoryMay 19, 2014 - 2:55 p.m.

CVE-2013-7040

2014-05-1914:55:09
CWE-310
web.nvd.nist.gov
314
cve
2013
7040
python
2.7
3.4
hash collisions
denial of service
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

8.2 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.6%

Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.

Affected configurations

NVD
Node
applemac_os_xRange≀10.10.4
Node
pythonpythonMatch2.7.1
OR
pythonpythonMatch2.7.1rc1
OR
pythonpythonMatch2.7.2rc1
OR
pythonpythonMatch2.7.3
OR
pythonpythonMatch2.7.4
OR
pythonpythonMatch2.7.5
OR
pythonpythonMatch2.7.6
OR
pythonpythonMatch2.7.7
OR
pythonpythonMatch2.7.1150
OR
pythonpythonMatch2.7.2150
OR
pythonpythonMatch3.0
OR
pythonpythonMatch3.0.1
OR
pythonpythonMatch3.1
OR
pythonpythonMatch3.1.1
OR
pythonpythonMatch3.1.2
OR
pythonpythonMatch3.1.3
OR
pythonpythonMatch3.1.4
OR
pythonpythonMatch3.1.5
OR
pythonpythonMatch3.2
OR
pythonpythonMatch3.2alpha
OR
pythonpythonMatch3.2.0
OR
pythonpythonMatch3.2.1
OR
pythonpythonMatch3.2.2
OR
pythonpythonMatch3.2.3
OR
pythonpythonMatch3.2.4
OR
pythonpythonMatch3.2.5
OR
pythonpythonMatch3.2.2150
OR
pythonpythonMatch3.3
OR
pythonpythonMatch3.3beta2
OR
pythonpythonMatch3.3.0
OR
pythonpythonMatch3.3.1
OR
pythonpythonMatch3.3.1rc1
OR
pythonpythonMatch3.3.2
OR
pythonpythonMatch3.3.3
OR
pythonpythonMatch3.3.3rc1
OR
pythonpythonMatch3.3.3rc2
OR
pythonpythonMatch3.3.4
OR
pythonpythonMatch3.3.4rc1
OR
pythonpythonMatch3.3.5-
OR
pythonpythonMatch3.3.5rc1
OR
pythonpythonMatch3.3.5rc2
CPENameOperatorVersion
apple:mac_os_xapple mac os xle10.10.4

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

8.2 High

AI Score

Confidence

High

0.007 Low

EPSS

Percentile

80.6%