CVE-2017-14158
Dashboard / Vulnerabilities / CVE-2017-14158
CVE-2017-14158
Published: 5 Sept 2017Last Modified: 8 Jul 2026
Aliases:
Summary:
Details: Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separate thread to a slow storage resource, as demonstrated by interaction between dataReceived (in core/downloader/handlers/http11.py) and S3FilesStore.
References: https://github.com/scrapy/scrapy/issues/482, http://blog.csdn.net/wangtua/article/details/75228728
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 5f69ec98f70e1e1e5f65fb36eb1cfb23d0be5b45
Fixed -None
Affected versions
1.4
1.4.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
