CVE-2012-1150

medium
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

References

http://bugs.python.org/issue13703

http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html

http://mail.python.org/pipermail/python-dev/2011-December/115116.html

http://mail.python.org/pipermail/python-dev/2012-January/115892.html

http://python.org/download/releases/2.6.8/

http://python.org/download/releases/2.7.3/

http://python.org/download/releases/3.1.5/

http://python.org/download/releases/3.2.3/

http://secunia.com/advisories/50858

http://secunia.com/advisories/51087

http://secunia.com/advisories/51089

http://www.openwall.com/lists/oss-security/2012/03/10/3

http://www.ubuntu.com/usn/USN-1592-1

http://www.ubuntu.com/usn/USN-1596-1

http://www.ubuntu.com/usn/USN-1615-1

http://www.ubuntu.com/usn/USN-1616-1

https://bugzilla.redhat.com/show_bug.cgi?id=750555

Details

Source: MITRE

Published: 2012-10-05

Updated: 2019-10-25

Type: CWE-310

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:python:python:0.9.0:*:*:*:*:*:*:*

cpe:2.3:a:python:python:0.9.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.5.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:1.6.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.0:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.0.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.1.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.2.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.5:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.3.7:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.4.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.5.150:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.4:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.5:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.6:*:*:*:*:*:*:*

cpe:2.3:a:python:python:*:*:*:*:*:*:*:* versions up to 2.6.7 (inclusive)

cpe:2.3:a:python:python:2.6.2150:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.6.6150:*:*:*:*:*:*:*

Configuration 2

OR

cpe:2.3:a:python:python:2.7.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.1:rc1:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.2:rc1:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.1150:*:*:*:*:*:*:*

cpe:2.3:a:python:python:2.7.2150:*:*:*:*:*:*:*

Configuration 3

OR

cpe:2.3:a:python:python:3.0:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.0.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.1:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.3:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.1.4:*:*:*:*:*:*:*

Configuration 4

OR

cpe:2.3:a:python:python:3.2:*:*:*:*:*:*:*

cpe:2.3:a:python:python:3.2:alpha:*:*:*:*:*:*

cpe:2.3:a:python:python:3.2.2150:*:*:*:*:*:*:*

Tenable Plugins

View all (35 total)

IDNameProductFamilySeverity
133259SUSE SLED15 / SLES15 Security Update : python (SUSE-SU-2020:0234-1) (BEAST) (httpoxy)NessusSuSE Local Security Checks
critical
133172openSUSE Security Update : python3 (openSUSE-2020-86) (BEAST) (httpoxy)NessusSuSE Local Security Checks
critical
133036SUSE SLED15 / SLES15 Security Update : python3 (SUSE-SU-2020:0114-1) (BEAST) (httpoxy)NessusSuSE Local Security Checks
critical
89039VMware ESX / ESXi Multiple Vulnerabilities (VMSA-2012-0016) (remote check)NessusMisc.
high
80749Oracle Solaris Third-Party Patch Update : python (multiple_vulnerabilities_in_python) (BEAST)NessusSolaris Local Security Checks
medium
79862ESXi 5.1 < Build 2323236 Third-Party Libraries Multiple Vulnerabilities (remote check) (BEAST)NessusMisc.
medium
74640openSUSE Security Update : python (openSUSE-SU-2012:0667-1) (BEAST)NessusSuSE Local Security Checks
medium
71811GLSA-201401-04 : Python: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
70561Mac OS X 10.x < 10.9 Multiple Vulnerabilities (BEAST)NessusMacOS X Local Security Checks
high
69705Amazon Linux AMI : python26 (ALAS-2012-98)NessusAmazon Linux Local Security Checks
medium
68546Oracle Linux 5 : python (ELSA-2012-0745)NessusOracle Linux Local Security Checks
medium
68545Oracle Linux 6 : python (ELSA-2012-0744)NessusOracle Linux Local Security Checks
medium
64221SuSE 11.1 Security Update : libpython2_6-1_0, libpython2_6-1_0-32bit, libpython2_6-1_0-x86, python, etc (SAT Patch Number 6310)NessusSuSE Local Security Checks
medium
64220SuSE 11.1 Security Update : libpython2_6-1_0, libpython2_6-1_0-32bit, libpython2_6-1_0-x86, python, etc (SAT Patch Number 6310)NessusSuSE Local Security Checks
medium
64108SuSE 11.1 Security Update : apache2-mod_python (SAT Patch Number 6247)NessusSuSE Local Security Checks
medium
62944VMSA-2012-0016 : VMware security updates for vSphere API and ESX Service ConsoleNessusVMware ESX Local Security Checks
high
62700Ubuntu 10.04 LTS / 11.04 : python3.1 vulnerabilities (USN-1616-1)NessusUbuntu Local Security Checks
medium
62677Ubuntu 11.04 / 11.10 / 12.04 LTS / 12.10 : python3.2 vulnerabilities (USN-1615-1)NessusUbuntu Local Security Checks
medium
62436Ubuntu 10.04 LTS / 11.04 / 11.10 : python2.6 vulnerabilities (USN-1596-1)NessusUbuntu Local Security Checks
medium
62410Ubuntu 11.04 / 11.10 : python2.7 vulnerabilities (USN-1592-1)NessusUbuntu Local Security Checks
medium
61956Mandriva Linux Security Advisory : python (MDVSA-2012:097)NessusMandriva Local Security Checks
medium
61523SuSE 10 Security Update : apache2-mod_python (ZYPP Patch Number 8127)NessusSuSE Local Security Checks
medium
61333Scientific Linux Security Update : python on SL6.x i386/x86_64 (20120618)NessusScientific Linux Local Security Checks
medium
61332Scientific Linux Security Update : python on SL5.x i386/x86_64 (20120618)NessusScientific Linux Local Security Checks
medium
59635Mandriva Linux Security Advisory : python (MDVSA-2012:096)NessusMandriva Local Security Checks
medium
59580Fedora 16 : python3-3.2.3-2.fc16 (2012-9135) (BEAST)NessusFedora Local Security Checks
medium
59570CentOS 6 : python (CESA-2012:0744)NessusCentOS Local Security Checks
medium
59564RHEL 5 : python (RHSA-2012:0745)NessusRed Hat Local Security Checks
medium
59563RHEL 6 : python (RHSA-2012:0744)NessusRed Hat Local Security Checks
medium
59560CentOS 5 : python (CESA-2012:0745)NessusCentOS Local Security Checks
medium
58997Fedora 16 : python-2.7.3-1.fc16 / python-docs-2.7.3-1.fc16 (2012-5924) (BEAST)NessusFedora Local Security Checks
medium
58996Fedora 17 : python3-3.2.3-5.fc17 (2012-5785) (BEAST)NessusFedora Local Security Checks
medium
58979Fedora 15 : python3-3.2.3-1.fc15 (2012-5916) (BEAST)NessusFedora Local Security Checks
medium
58956Fedora 17 : python-2.7.3-3.fc17 / python-docs-2.7.3-1.fc17 (2012-5892) (BEAST)NessusFedora Local Security Checks
medium
58891SuSE 10 Security Update : Python (ZYPP Patch Number 8080) (BEAST)NessusSuSE Local Security Checks
medium