ISOMAN

CVE

CVE-2021-3737

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. https://bugs.python.org/issue44022
  2. https://bugzilla.redhat.com/show_bug.cgi?id=1995162
  3. https://github.com/python/cpython/pull/25916
  4. https://github.com/python/cpython/pull/26503
  5. https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
  6. https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
  7. https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html
  8. https://security.netapp.com/advisory/ntap-20220407-0009/
  9. https://ubuntu.com/security/CVE-2021-3737
  10. https://www.oracle.com/security-alerts/cpujul2022.html
  11. https://bugs.python.org/issue44022
  12. https://bugzilla.redhat.com/show_bug.cgi?id=1995162
  13. https://github.com/python/cpython/pull/25916
  14. https://github.com/python/cpython/pull/26503
  15. https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html
  16. https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html
  17. https://lists.debian.org/debian-lts-announce/2024/11/msg00024.html
  18. https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html
  19. https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html
  20. https://security.netapp.com/advisory/ntap-20220407-0009/