Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.113933
Kategorie:Denial of Service
Titel:Python DoS Vulnerability (bpo-44394) - Mac OS X
Zusammenfassung:Python is prone to a denial of service (DoS) vulnerability.
Beschreibung:Summary:
Python is prone to a denial of service (DoS) vulnerability.

Vulnerability Insight:
On Windows and macOS, Python uses a vendored copy of libexpat
which is vulnerable to the XML 'Billion Laughs' expansion denial of service attack.

Updating libexpat copy in Python to libexpat 2.4.0 or newer fix the vulnerability.

Affected Software/OS:
Python versions prior to 3.6.15, 3.7.x prior to 3.7.12, 3.8.x
prior to 3.8.12 and 3.9.x prior to 3.9.7.

Solution:
Update to version 3.6.15, 3.7.12, 3.8.12, 3.9.7, 3.10.0 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2013-0340
1028213
http://securitytracker.com/id?1028213
20210921 APPLE-SA-2021-09-20-1 iOS 15 and iPadOS 15
http://seclists.org/fulldisclosure/2021/Sep/33
20210921 APPLE-SA-2021-09-20-2 watchOS 8
http://seclists.org/fulldisclosure/2021/Sep/34
20210921 APPLE-SA-2021-09-20-3 tvOS 15
http://seclists.org/fulldisclosure/2021/Sep/35
20210921 APPLE-SA-2021-09-20-6 Additional information for APPLE-SA-2021-09-13-1 iOS 14.8 and iPadOS 14.8
http://seclists.org/fulldisclosure/2021/Sep/38
20210921 APPLE-SA-2021-09-20-7 Additional information for APPLE-SA-2021-09-13-3 macOS Big Sur 11.6
http://seclists.org/fulldisclosure/2021/Sep/39
20210921 APPLE-SA-2021-09-20-8 Additional information for APPLE-SA-2021-09-13-4 Security Update 2021-005 Catalina
http://seclists.org/fulldisclosure/2021/Sep/40
20211027 APPLE-SA-2021-10-26-10 Additional information for APPLE-SA-2021-09-20-2 watchOS 8
http://seclists.org/fulldisclosure/2021/Oct/62
20211027 APPLE-SA-2021-10-26-11 Additional information for APPLE-SA-2021-09-20-3 tvOS 15
http://seclists.org/fulldisclosure/2021/Oct/63
20211027 APPLE-SA-2021-10-26-9 Additional information for APPLE-SA-2021-09-20-1 iOS 15 and iPadOS 15
http://seclists.org/fulldisclosure/2021/Oct/61
58233
http://www.securityfocus.com/bid/58233
90634
http://www.osvdb.org/90634
GLSA-201701-21
https://security.gentoo.org/glsa/201701-21
[announce] 20211007 CVE-2021-40439: Apache OpenOffice: Billion Laughs
https://lists.apache.org/thread.html/r41eca5f4f09e74436cbb05dec450fc2bef37b5d3e966aa7cc5fada6d%40%3Cannounce.apache.org%3E
[openoffice-users] 20211007 CVE-2021-40439: Apache OpenOffice: Billion Laughs
https://lists.apache.org/thread.html/rfb2c193360436e230b85547e85a41bea0916916f96c501f5b6fc4702%40%3Cusers.openoffice.apache.org%3E
[oss-security] 20130221 CVEs for libxml2 and expat internal and external XML entity expansion
http://openwall.com/lists/oss-security/2013/02/22/3
[oss-security] 20130413 Re-evaluating expat/libxml2 CVE assignments
http://www.openwall.com/lists/oss-security/2013/04/12/6
[oss-security] 20211007 CVE-2021-40439: Apache OpenOffice: Billion Laughs
http://www.openwall.com/lists/oss-security/2021/10/07/4
https://support.apple.com/kb/HT212804
https://support.apple.com/kb/HT212805
https://support.apple.com/kb/HT212807
https://support.apple.com/kb/HT212814
https://support.apple.com/kb/HT212815
https://support.apple.com/kb/HT212819
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.