![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.118267 |
Category: | Denial of Service |
Title: | Python < 2.6.8, 2.7.x < 2.7.3, 3.1.x < 3.1.5, 3.2.x < 3.2.3 XML-RPC DoS (bpo-14001) - Linux |
Summary: | Python is prone to a denial of service (DoS) vulnerability. |
Description: | Summary: Python is prone to a denial of service (DoS) vulnerability. Vulnerability Insight: SimpleXMLRPCServer.py in SimpleXMLRPCServer allows remote attackers to cause a DoS (infinite loop and CPU consumption) via an XML-RPC POST request that contains a smaller amount of data than specified by the Content-Length header. Affected Software/OS: Python prior to version 2.6.8, versions 2.7.x prior to 2.7.3, 3.1.x < 3.1.5 and 3.2.x prior to 3.2.3. Solution: Update to version 2.6.8, 2.7.3, 3.1.5, 3.2.3 or later. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2012-0845 http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html http://www.openwall.com/lists/oss-security/2012/02/13/4 http://www.securitytracker.com/id?1026689 http://secunia.com/advisories/50858 http://secunia.com/advisories/51024 http://secunia.com/advisories/51040 http://secunia.com/advisories/51087 http://secunia.com/advisories/51089 SuSE Security Announcement: openSUSE-SU-2020:0086 (Google Search) http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html http://www.ubuntu.com/usn/USN-1592-1 http://www.ubuntu.com/usn/USN-1596-1 http://www.ubuntu.com/usn/USN-1613-1 http://www.ubuntu.com/usn/USN-1613-2 http://www.ubuntu.com/usn/USN-1615-1 http://www.ubuntu.com/usn/USN-1616-1 |
Copyright | Copyright (C) 2021 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |