CVE-2013-7040
Summary
| CVE | CVE-2013-7040 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-19 14:55:09 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictably and makes it easier for context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1150. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Apple | Mac Os X | All | All | All | All |
| Application | Python | Python | 2.7.1 | All | All | All |
| Application | Python | Python | 2.7.1 | rc1 | All | All |
| Application | Python | Python | 2.7.1150 | All | All | All |
| Application | Python | Python | 2.7.2 | rc1 | All | All |
| Application | Python | Python | 2.7.2150 | All | All | All |
| Application | Python | Python | 2.7.3 | All | All | All |
| Application | Python | Python | 2.7.4 | All | All | All |
| Application | Python | Python | 2.7.5 | All | All | All |
| Application | Python | Python | 2.7.6 | All | All | All |
| Application | Python | Python | 2.7.7 | All | All | All |
| Application | Python | Python | 3.0 | All | All | All |
| Application | Python | Python | 3.0.1 | All | All | All |
| Application | Python | Python | 3.1 | All | All | All |
| Application | Python | Python | 3.1.1 | All | All | All |
| Application | Python | Python | 3.1.2 | All | All | All |
| Application | Python | Python | 3.1.3 | All | All | All |
| Application | Python | Python | 3.1.4 | All | All | All |
| Application | Python | Python | 3.1.5 | All | All | All |
| Application | Python | Python | 3.2 | All | All | All |
| Application | Python | Python | 3.2 | alpha | All | All |
| Application | Python | Python | 3.2.0 | All | All | All |
| Application | Python | Python | 3.2.1 | All | All | All |
| Application | Python | Python | 3.2.2 | All | All | All |
| Application | Python | Python | 3.2.2150 | All | All | All |
| Application | Python | Python | 3.2.3 | All | All | All |
| Application | Python | Python | 3.2.4 | All | All | All |
| Application | Python | Python | 3.2.5 | All | All | All |
| Application | Python | Python | 3.3 | All | All | All |
| Application | Python | Python | 3.3 | beta2 | All | All |
| Application | Python | Python | 3.3.0 | All | All | All |
| Application | Python | Python | 3.3.1 | All | All | All |
| Application | Python | Python | 3.3.1 | rc1 | All | All |
| Application | Python | Python | 3.3.2 | All | All | All |
| Application | Python | Python | 3.3.3 | All | All | All |
| Application | Python | Python | 3.3.3 | rc1 | All | All |
| Application | Python | Python | 3.3.3 | rc2 | All | All |
| Application | Python | Python | 3.3.4 | All | All | All |
| Application | Python | Python | 3.3.4 | rc1 | All | All |
| Application | Python | Python | 3.3.5 | - | All | All |
| Application | Python | Python | 3.3.5 | rc1 | All | All |
| Application | Python | Python | 3.3.5 | rc2 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| oss-security - CPython hash secret can be recoved remotely | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| APPLE-SA-2015-08-13-2 OS X Yosemite v10.10.5 and Security Update 2015-006 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006 - Apple Support | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | Vendor Advisory |
| oss-security - Re: CPython hash secret can be recoved remotely | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Python CVE-2013-7040 Information Disclosure Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Issue 14621: Hash function is not randomized properly - Python tracker | af854a3a-2127-422b-91ae-364da2661108 | bugs.python.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.