A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.
2022-09-09T14:15:08.660
2024-11-21T04:55:57.717
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | python | python | < 3.7.14 | Yes |
Application | python | python | < 3.8.14 | Yes |
Application | python | python | < 3.9.14 | Yes |
Application | python | python | < 3.10.7 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | python | python | 3.11.0 | Yes |
Application | redhat | quay | 3.0.0 | Yes |
Application | redhat | software_collections | - | Yes |
Operating System | fedoraproject | fedora | 35 | Yes |
Operating System | fedoraproject | fedora | 36 | Yes |
Operating System | fedoraproject | fedora | 37 | Yes |
Operating System | redhat | enterprise_linux | 8.0 | Yes |