UBUNTU-CVE-2017-14158
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14158
Summary:
Details: Scrapy 1.4 allows remote attackers to cause a denial of service (memory consumption) via large files because arbitrarily many files are read into memory, which is especially problematic if the files are then individually written in a separate thread to a slow storage resource, as demonstrated by interaction between dataReceived (in core/downloader/handlers/http11.py) and S3FilesStore.
References: https://ubuntu.com/security/CVE-2017-14158, http://blog.csdn.net/wangtua/article/details/75228728, https://github.com/scrapy/scrapy/issues/482, https://www.cve.org/CVERecord?id=CVE-2017-14158
Affected packages
Package
Name: python-scrapy
Purl: pkg:deb/ubuntu/python-scrapy?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
