← Back

CVE-2020-10735

nvd nist
Published: Sep 9, 2022Modified: Nov 3, 2025

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.

Affected (23)

1 product
Python
1 product
Fedora
3 products
Enterprise Linux
Quay
Software Collections
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Python
From 3.10.0 to 3.10.7
From 3.7.0 to 3.7.14
From 3.8.0 to 3.8.14
From 3.9.0 to 3.9.14
Version 3.11.0 alpha1
Version 3.11.0 alpha2
Version 3.11.0 alpha3
Version 3.11.0 alpha4
Version 3.11.0 alpha5
Version 3.11.0 alpha6
Version 3.11.0 alpha7
Version 3.11.0 beta1
Version 3.11.0 beta2
Version 3.11.0 beta3
Version 3.11.0 beta4
Version 3.11.0 beta5
Version 3.11.0 rc1
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Version 37
Version 8.0
Version 3.0.0
All versions

References (56)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.