In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Colander | Pylonsproject | * | 1.6 (including) |
| Python-colander | Ubuntu | esm-apps/xenial | * |
| Python-colander | Ubuntu | trusty | * |
| Python-colander | Ubuntu | xenial | * |