5
CVSSv2

CVE-2013-1753

Published: 11/03/2020 Updated: 21/10/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The gzip_decode function in the xmlrpc client library in Python 3.4 and previous versions allows remote malicious users to cause a denial of service (memory consumption) via a crafted HTTP request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python python

Vendor Advisories

Debian Bug report logs - #742927 python34: CVE-2013-1753 Package: src:python34; Maintainer for src:python34 is Matthias Klose <doko@debianorg>; Reported by: Michael Gilbert <mgilbert@debianorg> Date: Sat, 29 Mar 2014 01:57:02 UTC Severity: important Tags: help, security Found in version python34/340-1 Fixed ...
Several security issues were fixed in Python ...
It was discovered that multiple Python standard library modules implementing network protocols (such as httplib or smtplib) failed to restrict sizes of server responses A malicious server could cause a client using one of the affected modules to consume an excessive amount of memory(CVE-2013-1752) It was discovered that the Python xmlrpclib did n ...