Release date: 2012-10-07
Updated on: 2012-10-09
Affected Systems:
Python <2.6.8
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2012-1150
Python is an object-oriented, literal translation computer programming language.
When calculating hash values in versions earlier than Python 2.6.8, 2.7.x, 3.x, and 3.2.x, there is no pre-restriction on Hash conflicts. attackers can send a specially crafted application to applications that contain hash tables to support dos.
<* Source: vendor
Link: http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-1150
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Python
------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Www.python.org