Vulnerability Description
The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rencode Project | Rencode | <= 1.0.6 |
| Fedoraproject | Fedora | 34 |
Related Weaknesses (CWE)
References
- https://github.com/aresch/rencode/commit/572ff74586d9b1daab904c6f7f7009ce0143bb7PatchThird Party Advisory
- https://github.com/aresch/rencode/pull/29PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://pypi.org/project/rencode/#historyThird Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/16Mailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20211008-0001/Third Party Advisory
- https://github.com/aresch/rencode/commit/572ff74586d9b1daab904c6f7f7009ce0143bb7PatchThird Party Advisory
- https://github.com/aresch/rencode/pull/29PatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://pypi.org/project/rencode/#historyThird Party Advisory
- https://seclists.org/fulldisclosure/2021/Sep/16Mailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20211008-0001/Third Party Advisory
FAQ
What is CVE-2021-40839?
CVE-2021-40839 is a vulnerability with a CVSS score of 7.5 (HIGH). The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
How severe is CVE-2021-40839?
CVE-2021-40839 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40839?
Check the references section above for vendor advisories and patch information. Affected products include: Rencode Project Rencode, Fedoraproject Fedora.