CVE-2013-7040

EUVD-2013-6840
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
applemac_os_x
𝑥
≤ 10.10.4
pythonpython
2.7.1
pythonpython
2.7.1:rc1
pythonpython
2.7.2:rc1
pythonpython
2.7.3
pythonpython
2.7.4
pythonpython
2.7.5
pythonpython
2.7.6
pythonpython
2.7.7
pythonpython
2.7.1150
pythonpython
2.7.2150
pythonpython
3.0
pythonpython
3.0.1
pythonpython
3.1
pythonpython
3.1.1
pythonpython
3.1.2
pythonpython
3.1.3
pythonpython
3.1.4
pythonpython
3.1.5
pythonpython
3.2
pythonpython
3.2:alpha
pythonpython
3.2.0
pythonpython
3.2.1
pythonpython
3.2.2
pythonpython
3.2.3
pythonpython
3.2.4
pythonpython
3.2.5
pythonpython
3.2.2150
pythonpython
3.3
pythonpython
3.3:beta2
pythonpython
3.3.0
pythonpython
3.3.1
pythonpython
3.3.1:rc1
pythonpython
3.3.2
pythonpython
3.3.3
pythonpython
3.3.3:rc1
pythonpython
3.3.3:rc2
pythonpython
3.3.4
pythonpython
3.3.4:rc1
pythonpython
3.3.5
pythonpython
3.3.5:rc1
pythonpython
3.3.5:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python2.7
bullseye
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.6
lucid
ignored
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
python2.7
lucid
dne
precise
ignored
quantal
ignored
raring
ignored
saucy
ignored
trusty
ignored
python3.1
lucid
ignored
precise
dne
quantal
dne
raring
dne
saucy
dne
trusty
dne
python3.2
lucid
dne
precise
ignored
quantal
ignored
raring
dne
saucy
dne
trusty
dne
python3.3
lucid
dne
precise
dne
quantal
ignored
raring
ignored
saucy
ignored
trusty
dne
Common Weakness Enumeration