PSF-2022-4
Dashboard / Vulnerabilities / PSF-2022-4
PSF-2022-4
Summary: Prevent DoS by large str-int conversions
Details: A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
References: https://access.redhat.com/security/cve/CVE-2020-10735, https://github.com/python/cpython/issues/95778, https://github.com/pydantic/pydantic/issues/1477, https://lwn.net/Articles/907572/, https://pythoninsider.blogspot.com/2022/09/python-releases-3107-3914-3814-and-3714.html
Affected packages
Package
Name:
Purl:
