Bug 1078014 (CVE-2013-7338) - CVE-2013-7338 python: malformed ZIP files could cause 100% CPU usage
Summary: CVE-2013-7338 python: malformed ZIP files could cause 100% CPU usage
Alias: CVE-2013-7338
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 1078015
Blocks: 1078016
TreeView+ depends on / blocked
Reported: 2014-03-19 05:27 UTC by Murray McAllister
Modified: 2021-02-17 06:45 UTC (History)
14 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2016-11-03 21:06:52 UTC

Attachments (Terms of Use)

Description Murray McAllister 2014-03-19 05:27:38 UTC
A flaw was found in the way Python's zipfile module processed malformed ZIP files. Processing a malicious ZIP file could lead to 100% CPU usage. This would be an issue if you are running a web service that accepts and processes ZIP files from untrusted sources.

At least Python 3 is affected. It is not yet known if older versions (such as version 2.7) are affected.

Upstream fix: http://hg.python.org/cpython/rev/79ea4ce431b1

Original report: http://bugs.python.org/issue20078

CVE request: http://seclists.org/oss-sec/2014/q1/592

Comment 1 Murray McAllister 2014-03-19 05:31:37 UTC
Created python3 tracking bugs for this issue:

Affects: fedora-all [bug 1078015]

Comment 3 Martin Prpič 2014-03-19 16:10:43 UTC
MITRE assigned CVE-2013-7338 to this issue:


Comment 5 Stefan Cornelius 2014-04-01 13:56:05 UTC

This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5, 6 and 7.

Comment 6 Fedora Update System 2014-12-12 04:23:25 UTC
python3-3.3.2-19.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 8 Fedora Update System 2015-01-06 06:16:32 UTC
python3-3.3.2-11.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.

Note You need to log in before you can comment on or make changes to this bug.