Title: [3.7] gh-95778: CVE-2020-10735: Prevent DoS by very large int() by gpshead · Pull Request #96504 · python/cpython · GitHub
Open Graph Title: [3.7] gh-95778: CVE-2020-10735: Prevent DoS by very large int() by gpshead · Pull Request #96504 · python/cpython
X Title: [3.7] gh-95778: CVE-2020-10735: Prevent DoS by very large int() by gpshead · Pull Request #96504 · python/cpython
Description: Integer to and from text conversions via CPython's bignum int type is not safe against denial of service attacks due to malicious input. Very large input strings with hundred thousands of digits can consume several CPU seconds. This PR comes fresh from a pile of work done in our private PSRT security response team repo. This backports #96499 aka 511ca94 Issue: gh-95778 Signed-off-by: Christian Heimes [Red Hat] christian@python.org Tons-of-polishing-up-by: Gregory P. Smith [Google] greg@krypto.org Reviews via the private PSRT repo via many others (see the NEWS entry in the PR). I wrote up a one pager for the release managers. Additional review is wise on this 3.7 PR as the backport was more complicated due to internal Python config and startup code cleanup in 3.8 and onwards.
Open Graph Description: Integer to and from text conversions via CPython's bignum int type is not safe against denial of service attacks due to malicious input. Very large input strings with hundred thousands of digit...
X Description: Integer to and from text conversions via CPython's bignum int type is not safe against denial of service attacks due to malicious input. Very large input strings with hundred thousands of d...
Opengraph URL: https://github.com/python/cpython/pull/96504
X: @github
Domain: github.com
| route-pattern | /:user_id/:repository/pull/:id/checks(.:format) |
| route-controller | pull_requests |
| route-action | checks |
| fetch-nonce | v2:921dfb41-08fa-6d1d-7717-33f993fd2667 |
| current-catalog-service-hash | 87dc3bc62d9b466312751bfd5f889726f4f1337bdff4e8be7da7c93d6c00a25a |
| request-id | D70E:87739:1AEFFF4:25CAE44:696A50D5 |
| html-safe-nonce | 135a818608723a8ee0d9aa613a4f5137d809cf740bebe0104f6c9b500eceb073 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJENzBFOjg3NzM5OjFBRUZGRjQ6MjVDQUU0NDo2OTZBNTBENSIsInZpc2l0b3JfaWQiOiIzNTAxODQyNDA2MjA3ODAzNjA1IiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | ced863b5755685be22baf8ccf6518665084a02dee36b950a964227bfe7e775b3 |
| hovercard-subject-tag | pull_request:1044484546 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,checks,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/python/cpython/pull/96504/checks |
| twitter:image | https://avatars.githubusercontent.com/u/68491?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/u/68491?s=400&v=4 |
| og:image:alt | Integer to and from text conversions via CPython's bignum int type is not safe against denial of service attacks due to malicious input. Very large input strings with hundred thousands of digit... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 3f871c8e07f0ae1886fa8dac284166d28b09ad5bada6476fc10b674e489788ef |
| turbo-cache-control | no-preview |
| go-import | github.com/python/cpython git https://github.com/python/cpython.git |
| octolytics-dimension-user_id | 1525981 |
| octolytics-dimension-user_login | python |
| octolytics-dimension-repository_id | 81598961 |
| octolytics-dimension-repository_nwo | python/cpython |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 81598961 |
| octolytics-dimension-repository_network_root_nwo | python/cpython |
| turbo-body-classes | logged-out env-production page-responsive full-width full-width-p-0 |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 63c426b30d262aba269ef14c40e3c817b384cd61 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width