An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://pypi.org/project/future/ | product third party advisory |
https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215 | third party advisory |
https://github.com/python/cpython/pull/17157 | patch third party advisory exploit |
https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/ | vendor advisory exploit |
https://github.com/PythonCharmers/python-future/pull/610 | patch third party advisory issue tracking |