UBUNTU-CVE-2021-3737
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3737
UBUNTU-CVE-2021-3737
Summary:
Details: A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.
References: https://ubuntu.com/security/CVE-2021-3737, https://bugs.python.org/issue44022, https://github.com/python/cpython/pull/25916, https://github.com/python/cpython/pull/26503, https://github.com/python/cpython/commit/60ba0b68470a584103e28958d91e93a6db37ec92, https://github.com/python/cpython/commit/ea9327036680acc92d9f89eaf6f6a54d2f8d78d9, https://github.com/python/cpython/commit/f396864ddfe914531b5856d7bf852808ebfc01ae, https://github.com/python/cpython/commit/078b146f062d212919d0ba25e34e658a8234aa63, https://github.com/python/cpython/commit/f68d2d69f1da56c2aea1293ecf93ab69a6010ad7, https://github.com/python/cpython/commit/98e5a7975d99b58d511f171816ecdfb13d5cca18, https://github.com/python/cpython/commit/5df4abd6b033a5f1e48945c6988b45e35e76f647, https://github.com/python/cpython/commit/0389426fa4af4dfc8b1d7f3f291932d928392d8b, https://github.com/python/cpython/commit/fee96422e6f0056561cf74fef2012cc066c9db86, https://github.com/python/cpython/commit/1b6f4e5e13ebd1f957b47f7415b53d0869bdbac6, https://ubuntu.com/security/notices/USN-5083-1, https://ubuntu.com/security/notices/USN-5199-1, https://ubuntu.com/security/notices/USN-5200-1, https://ubuntu.com/security/notices/USN-5201-1, https://www.cve.org/CVERecord?id=CVE-2021-3737, https://ubuntu.com/security/notices/USN-6891-1
Affected packages
Package
Name: python3.4
Purl: pkg:deb/ubuntu/[email protected]~14.04.7+esm11?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
