UBUNTU-CVE-2020-10735
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-10735
Summary:
Details: A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
References: https://ubuntu.com/security/CVE-2020-10735, https://github.com/python/cpython/pull/96499, https://discuss.python.org/t/int-str-conversions-broken-in-latest-python-bugfix-releases/18889, https://lwn.net/Articles/907572/, https://seclists.org/oss-sec/2022/q3/215, https://github.com/python/cpython/issues/96834, https://www.cve.org/CVERecord?id=CVE-2020-10735
Affected packages
Package
Name: python2.7
Purl: pkg:deb/ubuntu/python2.7?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
