CVE-2013-7040

Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
VendorProductVersion
applemac_os_x
𝑥
≤ 10.10.4
pythonpython
2.7.1
pythonpython
2.7.1:rc1
pythonpython
2.7.2:rc1
pythonpython
2.7.3
pythonpython
2.7.4
pythonpython
2.7.5
pythonpython
2.7.6
pythonpython
2.7.7
pythonpython
2.7.1150
pythonpython
2.7.2150
pythonpython
3.0
pythonpython
3.0.1
pythonpython
3.1
pythonpython
3.1.1
pythonpython
3.1.2
pythonpython
3.1.3
pythonpython
3.1.4
pythonpython
3.1.5
pythonpython
3.2
pythonpython
3.2:alpha
pythonpython
3.2.0
pythonpython
3.2.1
pythonpython
3.2.2
pythonpython
3.2.3
pythonpython
3.2.4
pythonpython
3.2.5
pythonpython
3.2.2150
pythonpython
3.3
pythonpython
3.3:beta2
pythonpython
3.3.0
pythonpython
3.3.1
pythonpython
3.3.1:rc1
pythonpython
3.3.2
pythonpython
3.3.3
pythonpython
3.3.3:rc1
pythonpython
3.3.3:rc2
pythonpython
3.3.4
pythonpython
3.3.4:rc1
pythonpython
3.3.5
pythonpython
3.3.5:rc1
pythonpython
3.3.5:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python2.7
bullseye
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.6
trusty
dne
saucy
dne
raring
dne
quantal
dne
precise
dne
lucid
ignored
python2.7
trusty
ignored
saucy
ignored
raring
ignored
quantal
ignored
precise
ignored
lucid
dne
python3.1
trusty
dne
saucy
dne
raring
dne
quantal
dne
precise
dne
lucid
ignored
python3.2
trusty
dne
saucy
dne
raring
dne
quantal
ignored
precise
ignored
lucid
dne
python3.3
trusty
dne
saucy
ignored
raring
ignored
quantal
ignored
precise
dne
lucid
dne
Common Weakness Enumeration