CVE-2013-1753: xmlrpc gzip unlimited read

Add a default limit for the amount of data xmlrpclib.gzip_decode() will return.

  • Disclosure date: 2012-09-25 (Python issue #16043 reported)
  • Red Hat impact: Moderate

Fixed In

Python issue

xmlrpc: gzip_decode has unlimited read().

  • Python issue: issue #16043
  • Creation date: 2012-09-25
  • Reporter: Christian Heimes

Timeline

Timeline using the disclosure date 2012-09-25 as reference:

  • 2012-09-25: Python issue #16043 reported by Christian Heimes
  • 2014-12-06 (+802 days): commit 4e9cefa
  • 2014-12-06 (+802 days): commit 9e8f523
  • 2014-12-10 (+806 days): Python 2.7.9 released
  • 2015-02-23 (+881 days): Python 3.4.3 released
  • 2015-09-09: Python 3.5.0 released
  • 2017-09-19 (+1820 days): Python 3.3.7 released