ZeroHour

CVE-2021-3737

PoC
CVSS 3.1
7.5 high
EPSS
12%p96
Published
()
Modified
Description

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

Vendors
pythonredhatfedoraprojectcanonicalnetapporacle
Products
python, codeready linux builder, codeready linux builder for ibm z systems, codeready linux builder for power little endian, enterprise linux, enterprise linux for ibm z systems, enterprise linux for power little endian, fedora, ubuntu linux, hci, management services for element software, netapp xcp smb
Weakness
CWE-835, CWE-400
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.