PT-2024-7268 · Python+11 · Cpython+11
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
CPython versions prior to 3.13.0
Description:
The issue is related to the 'http.cookies' standard library module in CPython. When parsing cookies that contain backslashes for quoted characters in the cookie value, the parser uses an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value. This could allow a remote attacker to cause a denial of service. The estimated number of potentially affected devices is not specified.
Recommendations:
To resolve the issue, apply the available patch immediately to mitigate the risk of system slowdown or crash. As a temporary workaround, consider restricting the use of the 'http.cookies' module until a patch is available. Avoid using the
http.cookies module to parse cookies with backslashes for quoted characters in the cookie value until the issue is resolved.Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Cpython
Debian
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu