Show plain JSON{"affected_release": [{"advisory": "RHSA-2015:2101", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "python-0:2.7.5-34.el7", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2015-11-19T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-0:1.1-17.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-pip-0:1.5.6-5.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-setuptools-0:0.9.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-simplejson-0:3.2.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-wheel-0:0.24.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-0:1.1-17.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-pip-0:1.5.6-5.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-setuptools-0:0.9.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-simplejson-0:3.2.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-wheel-0:0.24.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-0:1.1-17.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-pip-0:1.5.6-5.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-setuptools-0:0.9.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-simplejson-0:3.2.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-wheel-0:0.24.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-0:1.1-20.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-0:2.7.8-3.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-pip-0:1.5.6-5.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-setuptools-0:0.9.8-5.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-simplejson-0:3.2.0-3.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-wheel-0:0.24.0-2.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}], "bugzilla": {"description": "python: XMLRPC library unrestricted decompression of HTTP responses using gzip enconding", "id": "1046170", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1046170"}, "csaw": false, "cvss": {"cvss_base_score": "4.3", "cvss_scoring_vector": "AV:N/AC:M/Au:N/C:N/I:N/A:P", "status": "verified"}, "cwe": "CWE-400", "details": ["The gzip_decode function in the xmlrpc client library in Python 3.4 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP request.", "It was discovered that the Python xmlrpclib did not restrict the size of a gzip compressed HTTP responses. A malicious XMLRPC server could cause an XMLRPC client using xmlrpclib to consume an excessive amount of memory."], "name": "CVE-2013-1753", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Not affected", "package_name": "python", "product_name": "Red Hat Enterprise Linux 5"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Not affected", "package_name": "jython", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Not affected", "package_name": "python", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:6", "fix_state": "Not affected", "package_name": "jython-eap6", "product_name": "Red Hat JBoss Enterprise Application Platform 6"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:4.3", "fix_state": "Not affected", "package_name": "jython", "product_name": "Red Hat JBoss SOA Platform 4.3"}, {"cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:5", "fix_state": "Not affected", "package_name": "jython", "product_name": "Red Hat JBoss SOA Platform 5"}, {"cpe": "cpe:/a:redhat:openshift:2", "fix_state": "Not affected", "package_name": "jython", "product_name": "Red Hat OpenShift Enterprise 2"}, {"cpe": "cpe:/a:redhat:network_satellite:5.4", "fix_state": "Not affected", "package_name": "jython", "product_name": "Red Hat Satellite 5.4"}, {"cpe": "cpe:/a:redhat:network_satellite:5.5", "fix_state": "Not affected", "package_name": "jython", "product_name": "Red Hat Satellite 5.5"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:1", "fix_state": "Affected", "package_name": "python27-python", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:2", "fix_state": "Will not fix", "package_name": "python33-python", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:2", "fix_state": "Not affected", "package_name": "rh-python34-python", "product_name": "Red Hat Software Collections"}], "public_date": "2012-09-25T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2013-1753\nhttps://nvd.nist.gov/vuln/detail/CVE-2013-1753"], "statement": "This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5 and 6 as their XMLRPC library did not include support for gzip encoded content.", "threat_severity": "Moderate"}