← Back

CVE-2013-7040

nvd nist
Published: May 19, 2014Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:N/A:P
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.

Affected (42)

Products: Apple: Mac Os X · Python: Python
1 product
Mac Os X
1 product
Python
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 10.10.4
Configuration B
41 vulnerable
Vulnerable SoftwareAffected Versions
Python
Version 2.7.1150
Version 2.7.1
Version 2.7.1 rc1
Version 2.7.2150
Version 2.7.2 rc1
Version 2.7.3
Version 2.7.4
Version 2.7.5
Version 2.7.6
Version 2.7.7
Version 3.0.1
Version 3.0
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1.5
Version 3.1
Version 3.2.0
Version 3.2.1
Version 3.2.2150
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2
Version 3.2 alpha
Version 3.3.0
Version 3.3.1
Version 3.3.1 rc1
Version 3.3.2
Version 3.3.3
Version 3.3.3 rc1
Version 3.3.3 rc2
Version 3.3.4
Version 3.3.4 rc1
Version 3.3.5
Version 3.3.5 rc1
Version 3.3.5 rc2
Version 3.3
Version 3.3 beta2

Related CWEs

References (12)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.