CVE-2012-0845
Publication date 14 February 2012
Last updated 24 July 2024
Ubuntu priority
SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the Content-Length header.
Status
Package | Ubuntu Release | Status |
---|---|---|
python2.4 | ||
python2.5 | ||
python2.6 | ||
python2.7 | ||
python3.1 | ||
python3.2 | ||
Notes
jdstrand
reproducer doesn't work on 8.04 LTS python2.4, but the code is sufficiently similar that we'll patch
Patch details
Package | Patch details |
---|---|
python2.6 | |
python2.7 | |
python3.1 | |
python3.2 |
References
Related Ubuntu Security Notices (USN)
- USN-1613-1
- Python 2.5 vulnerabilities
- 17 October 2012
- USN-1592-1
- Python 2.7 vulnerabilities
- 2 October 2012
- USN-1613-2
- Python 2.4 vulnerabilities
- 17 October 2012
- USN-1616-1
- Python 3.1 vulnerabilities
- 24 October 2012
- USN-1615-1
- Python 3.2 vulnerabilities
- 23 October 2012
- USN-1596-1
- Python 2.6 vulnerabilities
- 4 October 2012