Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1078014 - (CVE-2013-7338) CVE-2013-7338 python: malformed ZIP files could cause 100% CPU usage
CVE-2013-7338 python: malformed ZIP files could cause 100% CPU usage
Status: CLOSED WONTFIX
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20131227,repor...
: Security
Depends On: 1078015
Blocks: 1078016
  Show dependency treegraph
 
Reported: 2014-03-19 01:27 EDT by Murray McAllister
Modified: 2016-11-03 17:06 EDT (History)
14 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-11-03 17:06:52 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Murray McAllister 2014-03-19 01:27:38 EDT
A flaw was found in the way Python's zipfile module processed malformed ZIP files. Processing a malicious ZIP file could lead to 100% CPU usage. This would be an issue if you are running a web service that accepts and processes ZIP files from untrusted sources.

At least Python 3 is affected. It is not yet known if older versions (such as version 2.7) are affected.

Upstream fix: http://hg.python.org/cpython/rev/79ea4ce431b1

Original report: http://bugs.python.org/issue20078

CVE request: http://seclists.org/oss-sec/2014/q1/592
Comment 1 Murray McAllister 2014-03-19 01:31:37 EDT
Created python3 tracking bugs for this issue:

Affects: fedora-all [bug 1078015]
Comment 3 Martin Prpič 2014-03-19 12:10:43 EDT
MITRE assigned CVE-2013-7338 to this issue:

http://seclists.org/oss-sec/2014/q1/595
Comment 5 Stefan Cornelius 2014-04-01 09:56:05 EDT
Statement:

This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7.
Comment 6 Fedora Update System 2014-12-11 23:23:25 EST
python3-3.3.2-19.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2015-01-06 01:16:32 EST
python3-3.3.2-11.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.