CVE-2012-0845

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

SimpleXMLRPCServer.py in SimpleXMLRPCServer in Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the Content-Length header.

References

http://bugs.python.org/issue14001

http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html

http://python.org/download/releases/2.6.8/

http://python.org/download/releases/2.7.3/

http://python.org/download/releases/3.1.5/

http://python.org/download/releases/3.2.3/

http://secunia.com/advisories/50858

http://secunia.com/advisories/51024

http://secunia.com/advisories/51040

http://secunia.com/advisories/51087

http://secunia.com/advisories/51089

http://www.openwall.com/lists/oss-security/2012/02/13/4

http://www.securitytracker.com/id?1026689

http://www.ubuntu.com/usn/USN-1592-1

http://www.ubuntu.com/usn/USN-1596-1

http://www.ubuntu.com/usn/USN-1613-1

http://www.ubuntu.com/usn/USN-1613-2

http://www.ubuntu.com/usn/USN-1615-1

http://www.ubuntu.com/usn/USN-1616-1

https://bugzilla.redhat.com/show_bug.cgi?id=789790

Details

Source: MITRE

Published: 2012-10-05

Updated: 2019-10-25

Type: CWE-399

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:python:python:0.9.0:*:*:*:*:*:*:*

cpe:2.3:a:python:python:0.9.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.5.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.6.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.0:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.5:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.7:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.150:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.5:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:*:*:*:*:*:*:*:* versions up to 2.6.7 (inclusive)

cpe:2.3:a:python:python:2.6.2150:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.6150:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:python:python:2.7.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.1:rc1:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.2:rc1:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.1150:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.2150:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.0.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.4:*:*:*:*:*:*:*

Configuration 4

OR

cpe:2.3:a:python:python:3.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.2:alpha:*:*:*:*:*:*

cpe:2.3:a:python:python:3.2.2150:*:*:*:*:*:*:*

Tenable Plugins

View all (31 total)

IDNameProductFamilySeverity
133259SUSE SLED15 / SLES15 Security Update : python (SUSE-SU-2020:0234-1) (BEAST) (httpoxy)NessusSuSE Local Security Checks
critical
133172openSUSE Security Update : python3 (openSUSE-2020-86) (BEAST) (httpoxy)NessusSuSE Local Security Checks
critical
133036SUSE SLED15 / SLES15 Security Update : python3 (SUSE-SU-2020:0114-1) (BEAST) (httpoxy)NessusSuSE Local Security Checks
critical
80749Oracle Solaris Third-Party Patch Update : python (multiple_vulnerabilities_in_python) (BEAST)NessusSolaris Local Security Checks
medium
79862ESXi 5.1 < Build 2323236 Third-Party Libraries Multiple Vulnerabilities (remote check) (BEAST)NessusMisc.
medium
74640openSUSE Security Update : python (openSUSE-SU-2012:0667-1) (BEAST)NessusSuSE Local Security Checks
medium
71811GLSA-201401-04 : Python: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
70561Mac OS X 10.x < 10.9 Multiple Vulnerabilities (BEAST)NessusMacOS X Local Security Checks
high
69705Amazon Linux AMI : python26 (ALAS-2012-98)NessusAmazon Linux Local Security Checks
medium
69688Amazon Linux AMI : python27 (ALAS-2012-81)NessusAmazon Linux Local Security Checks
medium
69687Amazon Linux AMI : python26 (ALAS-2012-80)NessusAmazon Linux Local Security Checks
medium
68545Oracle Linux 6 : python (ELSA-2012-0744)NessusOracle Linux Local Security Checks
medium
64221SuSE 11.1 Security Update : libpython2_6-1_0, libpython2_6-1_0-32bit, libpython2_6-1_0-x86, python, etc (SAT Patch Number 6310)NessusSuSE Local Security Checks
medium
64220SuSE 11.1 Security Update : libpython2_6-1_0, libpython2_6-1_0-32bit, libpython2_6-1_0-x86, python, etc (SAT Patch Number 6310)NessusSuSE Local Security Checks
medium
62700Ubuntu 10.04 LTS / 11.04 : python3.1 vulnerabilities (USN-1616-1)NessusUbuntu Local Security Checks
medium
62677Ubuntu 11.04 / 11.10 / 12.04 LTS / 12.10 : python3.2 vulnerabilities (USN-1615-1)NessusUbuntu Local Security Checks
medium
62620Ubuntu 8.04 LTS : python2.4 vulnerabilities (USN-1613-2)NessusUbuntu Local Security Checks
medium
62619Ubuntu 8.04 LTS : python2.5 vulnerabilities (USN-1613-1)NessusUbuntu Local Security Checks
medium
62436Ubuntu 10.04 LTS / 11.04 / 11.10 : python2.6 vulnerabilities (USN-1596-1)NessusUbuntu Local Security Checks
medium
62410Ubuntu 11.04 / 11.10 : python2.7 vulnerabilities (USN-1592-1)NessusUbuntu Local Security Checks
medium
61956Mandriva Linux Security Advisory : python (MDVSA-2012:097)NessusMandriva Local Security Checks
medium
61333Scientific Linux Security Update : python on SL6.x i386/x86_64 (20120618)NessusScientific Linux Local Security Checks
medium
59635Mandriva Linux Security Advisory : python (MDVSA-2012:096)NessusMandriva Local Security Checks
medium
59580Fedora 16 : python3-3.2.3-2.fc16 (2012-9135) (BEAST)NessusFedora Local Security Checks
medium
59570CentOS 6 : python (CESA-2012:0744)NessusCentOS Local Security Checks
medium
59563RHEL 6 : python (RHSA-2012:0744)NessusRed Hat Local Security Checks
medium
58997Fedora 16 : python-2.7.3-1.fc16 / python-docs-2.7.3-1.fc16 (2012-5924) (BEAST)NessusFedora Local Security Checks
medium
58996Fedora 17 : python3-3.2.3-5.fc17 (2012-5785) (BEAST)NessusFedora Local Security Checks
medium
58979Fedora 15 : python3-3.2.3-1.fc15 (2012-5916) (BEAST)NessusFedora Local Security Checks
medium
58956Fedora 17 : python-2.7.3-3.fc17 / python-docs-2.7.3-1.fc17 (2012-5892) (BEAST)NessusFedora Local Security Checks
medium
57926FreeBSD : Python -- DoS via malformed XML-RPC / HTTP POST request (b4f8be9e-56b2-11e1-9fb7-003067b2972c)NessusFreeBSD Local Security Checks
medium