BIT-python-2023-36632

    Dashboard / Vulnerabilities / BIT-python-2023-36632

    BIT-python-2023-36632

    Published: 6 Mar 2024Last Modified: 8 Sept 2026

    Summary:

    Details: The legacy email.utils.parseaddr function in Python through 3.11.4 allows attackers to trigger "RecursionError: maximum recursion depth exceeded while calling a Python object" via a crafted argument. This argument is plausibly an untrusted value from an application's input data that was supposed to contain a name and an e-mail address. NOTE: email.utils.parseaddr is categorized as a Legacy API in the documentation of the Python email package. Applications should instead use the email.parser.BytesParser or email.parser.Parser class. NOTE: the vendor's perspective is that this is neither a vulnerability nor a bug. The email package is intended to have size limits and to throw an exception when limits are exceeded; they were exceeded by the example demonstration code.

    Affected packages

    Package

    Name: python

    Purl: pkg:bitnami/python

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.11.5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-python-2023-36632 | CVE-DB