Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork33.7k
Closed
Labels
3.10only security fixes3.11only security fixes3.12only security fixes3.13bugs and security fixes3.14bugs and security fixes3.15new features, bugs and security fixes3.9 (EOL)end of lifestdlibStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errortype-securityA security issue
Description
Bug Description:
A series of simple quadratic complexity vulnerabilities has been identified. After confirmation by CPython's security team, since these DOS vulnerabilities pose a low threat and are relatively tedious to exploit, we can directly initiate requests in issues to seek assistance from the community for fixes.
Vulnerability Locations (All Fixed):
- Vulnerabilities have been fixed ingh-136065: Fix quadratic complexity in os.path.expandvars() #134952 by@serhiy-storchaka and@Wulian233.
Common Information:
- CPython Version: main branch
- Operating System: Linux
- Credits: Finder is kexinoh (Xiangfan Wu) from QI-ANXIN Technology Research Institute.
Linked PRs
- gh-136065: Fix quadratic complexity in os.path.expandvars() #134952
- [3.9] gh-136065: Fix quadratic complexity in os.path.expandvars() (GH-134952) #140839
- [3.14] gh-136065: Fix quadratic complexity in os.path.expandvars() (GH-134952) #140844
- [3.13] gh-136065: Fix quadratic complexity in os.path.expandvars() (GH-134952) #140845
- [3.12] gh-136065: Fix quadratic complexity in os.path.expandvars() (GH-134952) #140847
- [3.11] gh-136065: Fix quadratic complexity in os.path.expandvars() (GH-134952) #140848
- [3.10] gh-136065: Fix quadratic complexity in os.path.expandvars() (GH-134952) #140851
Metadata
Metadata
Assignees
Labels
3.10only security fixes3.11only security fixes3.12only security fixes3.13bugs and security fixes3.14bugs and security fixes3.15new features, bugs and security fixes3.9 (EOL)end of lifestdlibStandard Library Python modules in the Lib/ directorytype-bugAn unexpected behavior, bug, or errortype-securityA security issue