CVE-2013-7338
Detail
Modified After Enrichment
This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes.
Description
Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.
Metrics
CVSS Version 4.0
CVSS Version 3.x
CVSS Version 2.0
NVD enrichment efforts reference publicly available information to associate
vector strings. CVSS information contributed by other sources is also
displayed.
CVSS 4.0 Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 3.x Severity and Vector Strings:
NVD assessment
not yet provided.
CVSS 2.0 Severity and Vector Strings:
Vector:
(AV:N/AC:M/Au:N/C:N/I:N/A:C)
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace.
We have provided these links to other web sites because they
may have information that would be of interest to you. No
inferences should be drawn on account of other sites being
referenced, or not, from this page. There may be other web
sites that are more appropriate for your purpose. NIST does
not necessarily endorse the views expressed, or concur with
the facts presented on these sites. Further, NIST does not
endorse any commercial products that may be mentioned on
these sites. Please address comments about this page to [email protected] .
URL
Source(s)
Tag(s)
http://bugs.python.org/issue20078
CVE, MITRE
Exploit
Patch
Vendor Advisory
http://hg.python.org/cpython/rev/79ea4ce431b1
CVE, MITRE
Exploit
Patch
Vendor Advisory
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
CVE, MITRE
Mailing List
http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html
CVE, MITRE
Mailing List
Third Party Advisory
http://seclists.org/oss-sec/2014/q1/592
CVE, MITRE
Mailing List
Third Party Advisory
http://seclists.org/oss-sec/2014/q1/595
CVE, MITRE
Mailing List
Third Party Advisory
http://www.securityfocus.com/bid/65179
CVE, MITRE
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id/1029973
CVE, MITRE
Third Party Advisory
VDB Entry
https://docs.python.org/3.3/whatsnew/changelog.html
CVE, MITRE
Vendor Advisory
https://security.gentoo.org/glsa/201503-10
CVE, MITRE
Third Party Advisory
https://support.apple.com/kb/HT205031
CVE, MITRE
Patch
Vendor Advisory
Weakness Enumeration
CWE-ID
CWE Name
Source
CWE-20
Improper Input Validation
NIST
Change History
10 change records found show changes
CVE Modified by MITRE
6/16/2026 8:01:47 PM
Action
Type
Old Value
New Value
Added
Affected
[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]
CVE Status Change
5/06/2026 6:30:45 PM
Action
Type
Old Value
New Value
CVE Modified by CVE
11/20/2024 9:00:46 PM
Action
Type
Old Value
New Value
Added
Reference
http://bugs.python.org/issue20078
Added
Reference
http://hg.python.org/cpython/rev/79ea4ce431b1
Added
Reference
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Added
Reference
http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html
Added
Reference
http://seclists.org/oss-sec/2014/q1/592
Added
Reference
http://seclists.org/oss-sec/2014/q1/595
Added
Reference
http://www.securityfocus.com/bid/65179
Added
Reference
http://www.securitytracker.com/id/1029973
Added
Reference
https://docs.python.org/3.3/whatsnew/changelog.html
Added
Reference
https://security.gentoo.org/glsa/201503-10
Added
Reference
https://support.apple.com/kb/HT205031
CVE Modified by MITRE
5/13/2024 11:05:39 PM
Action
Type
Old Value
New Value
Modified Analysis by NIST
8/21/2019 8:41:11 AM
Action
Type
Old Value
New Value
Changed
CPE Configuration
OR
*cpe:2.3:a:python:python:3.3:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3:beta2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.1:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc2:*:*:*:*:*:*
*cpe:2.3:a:python:python:*:rc1:*:*:*:*:*:* versions up to (including) 3.3.4
OR
*cpe:2.3:a:python:python:3.3.0:-:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:alpha1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:alpha2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:alpha3:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:alpha4:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:beta1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:beta2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:rc2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:rc3:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.1:-:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.1:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc2:*:*:*:*:*:*
Changed
Reference Type
http://bugs.python.org/issue20078 Exploit, Patch
http://bugs.python.org/issue20078 Exploit, Patch, Vendor Advisory
Changed
Reference Type
http://hg.python.org/cpython/rev/79ea4ce431b1 Exploit, Patch
http://hg.python.org/cpython/rev/79ea4ce431b1 Exploit, Patch, Vendor Advisory
Changed
Reference Type
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html No Types Assigned
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html Mailing List
Changed
Reference Type
http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html No Types Assigned
http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html Mailing List, Third Party Advisory
Changed
Reference Type
http://seclists.org/oss-sec/2014/q1/592 No Types Assigned
http://seclists.org/oss-sec/2014/q1/592 Mailing List, Third Party Advisory
Changed
Reference Type
http://seclists.org/oss-sec/2014/q1/595 No Types Assigned
http://seclists.org/oss-sec/2014/q1/595 Mailing List, Third Party Advisory
Changed
Reference Type
http://www.securityfocus.com/bid/65179 No Types Assigned
http://www.securityfocus.com/bid/65179 Third Party Advisory, VDB Entry
Changed
Reference Type
http://www.securitytracker.com/id/1029973 No Types Assigned
http://www.securitytracker.com/id/1029973 Third Party Advisory, VDB Entry
Changed
Reference Type
https://docs.python.org/3.3/whatsnew/changelog.html No Types Assigned
https://docs.python.org/3.3/whatsnew/changelog.html Vendor Advisory
Changed
Reference Type
https://security.gentoo.org/glsa/201503-10 No Types Assigned
https://security.gentoo.org/glsa/201503-10 Third Party Advisory
CVE Modified by MITRE
6/30/2017 9:29:04 PM
Action
Type
Old Value
New Value
Added
Reference
https://security.gentoo.org/glsa/201503-10 [No Types Assigned]
CVE Modified by MITRE
11/28/2016 2:10:09 PM
Action
Type
Old Value
New Value
Added
Reference
http://www.securityfocus.com/bid/65179 [No Types Assigned]
Modified Analysis by NIST
3/30/2016 5:57:15 PM
Action
Type
Old Value
New Value
Changed
CPE Configuration
Configuration 1
OR
*cpe:2.3:a:python:python:3.3.1:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.4:rc1:*:*:*:*:*:* (and previous)
*cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3:beta2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3:*:*:*:*:*:*:*
Configuration 1
OR
*cpe:2.3:a:python:python:3.3.1:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc1:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.3:rc2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.4:rc1:*:*:*:*:*:* (and previous)
*cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3:beta2:*:*:*:*:*:*
*cpe:2.3:a:python:python:3.3:*:*:*:*:*:*:*
Configuration 2
OR
*cpe:2.3:o:apple:mac_os_x:10.10.4:*:*:*:*:*:*:* (and previous)
Changed
Reference Type
https://support.apple.com/kb/HT205031 No Types Assigned
https://support.apple.com/kb/HT205031 Advisory, Patch
CVE Modified by MITRE
8/17/2015 9:59:24 PM
Action
Type
Old Value
New Value
Added
Reference
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
Added
Reference
https://support.apple.com/kb/HT205031
Initial CVE Analysis
4/23/2014 8:28:47 AM
Action
Type
Old Value
New Value
Quick Info
CVE Dictionary Entry: CVE-2013-7338 NVD
Published Date: 04/22/2014 NVD
Last Modified: 06/16/2026
Source: MITRE