HIGH · 7.5

CVE-2021-3737

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite...

Vulnerability Description

A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
PythonPython>= 3.6.0, < 3.6.14
RedhatCodeready Linux Builder8.0
RedhatCodeready Linux Builder For Ibm Z Systems8.0
RedhatCodeready Linux Builder For Power Little Endian8.0
RedhatEnterprise Linux6.0
RedhatEnterprise Linux For Ibm Z Systems8.0
RedhatEnterprise Linux For Power Little Endian8.0
FedoraprojectFedora33
CanonicalUbuntu Linux14.04
NetappHci-
NetappManagement Services For Element Software-
NetappNetapp Xcp Smb-
NetappOntap Select Deploy Administration Utility-
NetappXcp Nfs-
OracleCommunications Cloud Native Core Binding Support Function22.1.3
OracleCommunications Cloud Native Core Network Exposure Function22.1.1
OracleCommunications Cloud Native Core Policy22.2.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3737?

CVE-2021-3737 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite...

How severe is CVE-2021-3737?

CVE-2021-3737 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3737?

Check the references section above for vendor advisories and patch information. Affected products include: Python Python, Redhat Codeready Linux Builder, Redhat Codeready Linux Builder For Ibm Z Systems, Redhat Codeready Linux Builder For Power Little Endian, Redhat Enterprise Linux.