Rejected reason: Various versions of Python do not properly restrict readline calls, which allows remote attackers to cause a denial of service (memory consumption) via a long string, related to (1) httplib - fixed in 2.7.4, 2.6.9, and 3.3.3; (2) ftplib - fixed in 2.7.6, 2.6.9, 3.3.3; (3) imaplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; (4) nntplib - fixed in 2.7.6, 2.6.9, 3.3.3; (5) poplib - not yet fixed in 2.7.x, fixed in 2.6.9, 3.3.3; and (6) smtplib - not yet fixed in 2.7.x, fixed in 2.6.9, not yet fixed in 3.3.x. NOTE: this was REJECTed because it is incompatible with CNT1 "Independently Fixable" in the CVE Counting Decisions
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | — | May 3, 2019 | Jun 25, 2015 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 21, 2017 |
| Gentoo Linux | — | — | Oct 30, 2017 | Mar 18, 2015 |
| Oracle Solaris | — | — | May 29, 2017 | May 29, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jun 3, 2019 |
| Suse | — | — | Mar 7, 2014 | Mar 7, 2014 |
| Ubuntu | — | Upgrade python2.7-minimalUpgrade python3.4Upgrade python2.7Upgrade python3.2-minimalUpgrade python3.2Upgrade python3.4-minimal | Nov 8, 2024 | Jun 3, 2019 |
| Vmsa 2014 0012 | — | — | Oct 28, 2015 | Dec 4, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub