Unrated severityNVD Advisory· Published Jun 18, 2020· Updated Aug 4, 2024
CVE-2020-14422
CVE-2020-14422
Description
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.
Affected products
121- Python/Pythondescription
- osv-coords120 versionspkg:bitnami/libpythonpkg:bitnami/pythonpkg:bitnami/python-minpkg:rpm/almalinux/python38-asn1cryptopkg:rpm/almalinux/python38-cffipkg:rpm/almalinux/python38-chardetpkg:rpm/almalinux/python38-cryptographypkg:rpm/almalinux/python38-Cythonpkg:rpm/almalinux/python38-idnapkg:rpm/almalinux/python38-markupsafepkg:rpm/almalinux/python38-mod_wsgipkg:rpm/almalinux/python38-psycopg2pkg:rpm/almalinux/python38-psycopg2-docpkg:rpm/almalinux/python38-psycopg2-testspkg:rpm/almalinux/python38-pycparserpkg:rpm/almalinux/python38-pysockspkg:rpm/almalinux/python38-pytzpkg:rpm/almalinux/python38-requestspkg:rpm/almalinux/python38-scipypkg:rpm/opensuse/python36&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python3-base&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/python3-base&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python3-core&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/python3-core&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python3-doc&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python3-documentation&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/python3-documentation&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python-ipaddress&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/python-ipaddress&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/python36-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python36-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python3-base&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python3-base&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/python3-base&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/python3-base&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python3-base&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python3-base&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python3-base&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP1pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/python3&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python3&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2012pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/python3&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/python3&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python3&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python3&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python3&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/python-ipaddress&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/python-ipaddress&distro=SUSE%20Enterprise%20Storage%205pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP1pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%202%2015%20SP2pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSSpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/python-ipaddress&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/python-ipaddress&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/python-ipaddress&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/python-ipaddress&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-ipaddress&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/python-ipaddress&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
>= 3.0.0, < 3.5.10+ 119 more
- (no CPE)range: >= 3.0.0, < 3.5.10
- (no CPE)range: >= 3.0.0, < 3.5.10
- (no CPE)range: >= 3.0.0, < 3.5.10
- (no CPE)range: < 1.2.0-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.13.2-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 3.0.4-19.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 0.29.14-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.1.1-6.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 4.6.8-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8.4-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8.4-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.8.4-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.19-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.7.1-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2019.3-3.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 2.22.0-9.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 1.3.1-4.module_el8.6.0+2778+cd494b30
- (no CPE)range: < 3.6.15-1.1
- (no CPE)range: < 3.6.10-lp151.6.21.1
- (no CPE)range: < 3.6.10-lp152.4.3.1
- (no CPE)range: < 3.6.12-lp151.6.32.1
- (no CPE)range: < 3.6.12-lp152.4.14.1
- (no CPE)range: < 3.6.10-lp151.6.21.1
- (no CPE)range: < 3.6.10-lp152.4.3.1
- (no CPE)range: < 3.6.10-lp152.4.3.1
- (no CPE)range: < 3.6.12-lp151.6.32.1
- (no CPE)range: < 3.6.12-lp152.4.14.1
- (no CPE)range: < 1.0.18-lp151.3.3.1
- (no CPE)range: < 1.0.18-lp152.4.3.1
- (no CPE)range: < 3.6.10-4.17.1
- (no CPE)range: < 3.6.10-4.17.1
- (no CPE)range: < 3.6.12-4.22.2
- (no CPE)range: < 3.6.12-4.22.2
- (no CPE)range: < 3.6.10-4.17.1
- (no CPE)range: < 3.6.10-4.17.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.6.12-3.67.2
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.6.10-3.56.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 3.4.10-25.52.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.18-3.13.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.22-3.3.1
- (no CPE)range: < 1.0.18-3.3.1
- (no CPE)range: < 1.0.22-3.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
24- lists.opensuse.org/opensuse-security-announce/2020-07/msg00003.htmlmitrevendor-advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00006.htmlmitrevendor-advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00032.htmlmitrevendor-advisory
- lists.opensuse.org/opensuse-security-announce/2020-07/msg00041.htmlmitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/36XI3EEQNMHGOZEI63Y7UV6XZRELYEAU/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNHPQGSP2YM3JAUD2VAMPXTIUQTZ2M2U/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CTUNTBJ3POHONQOTLEZC46POCIYYTAKZ/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FCCZTAYZATTNSNEAXWA7U3HCO2OVQKT5/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LE4O3PNDNNOMSKHNUKZKD3NGHIFUFDPX/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTBKKOLFFNHG6CM4ACDX4APHSD5ZX5N4/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OXI72HIHMXCQFWTULUXDG7VDA2BCYL4Y/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V3TALOUBYU2MQD4BPLRTDQUMBKGCAXUA/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V53P2YOLEQH4J7S5QHXMKMZYFTVVMTMO/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VT4AF72TJ2XNIKCR4WEBR7URBJJ4YZRD/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X36Y523UAZY5QFXZAAORNFY63HLBWX7N/mitrevendor-advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YILCHHTNLH4GG4GSQBX2MZRKZBXOLCKE/mitrevendor-advisory
- security.gentoo.org/glsa/202008-01mitrevendor-advisory
- usn.ubuntu.com/4428-1/mitrevendor-advisory
- lists.debian.org/debian-lts-announce/2020/07/msg00011.htmlmitremailing-list
- lists.debian.org/debian-lts-announce/2023/05/msg00016.htmlmitremailing-list
- bugs.python.org/issue41004mitre
- github.com/python/cpython/pull/20956mitre
- security.netapp.com/advisory/ntap-20200724-0004/mitre
- www.oracle.com/security-alerts/cpujan2021.htmlmitre
News mentions
0No linked articles in our index yet.