CVE Vulnerabilities

CVE-2020-10735

Incorrect Type Conversion or Cast

Published: Sep 09, 2022 | Modified: Jun 30, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
NEGLIGIBLE

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int(text), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

Name Vendor Start Version End Version
Python Python 3.7.0 (including) 3.7.14 (excluding)
Python Python 3.8.0 (including) 3.8.14 (excluding)
Python Python 3.9.0 (including) 3.9.14 (excluding)
Python Python 3.10.0 (including) 3.10.7 (excluding)
Python Python 3.11.0-alpha1 (including) 3.11.0-alpha1 (including)
Python Python 3.11.0-alpha2 (including) 3.11.0-alpha2 (including)
Python Python 3.11.0-alpha3 (including) 3.11.0-alpha3 (including)
Python Python 3.11.0-alpha4 (including) 3.11.0-alpha4 (including)
Python Python 3.11.0-alpha5 (including) 3.11.0-alpha5 (including)
Python Python 3.11.0-alpha6 (including) 3.11.0-alpha6 (including)
Python Python 3.11.0-alpha7 (including) 3.11.0-alpha7 (including)
Python Python 3.11.0-beta1 (including) 3.11.0-beta1 (including)
Python Python 3.11.0-beta2 (including) 3.11.0-beta2 (including)
Python Python 3.11.0-beta3 (including) 3.11.0-beta3 (including)
Python Python 3.11.0-beta4 (including) 3.11.0-beta4 (including)
Python Python 3.11.0-beta5 (including) 3.11.0-beta5 (including)
Python Python 3.11.0-rc1 (including) 3.11.0-rc1 (including)
Python Ubuntu trusty *
Python Ubuntu xenial *
Python2.7 Ubuntu bionic *
Python2.7 Ubuntu devel *
Python2.7 Ubuntu esm-apps/focal *
Python2.7 Ubuntu esm-apps/jammy *
Python2.7 Ubuntu esm-infra-legacy/trusty *
Python2.7 Ubuntu esm-infra/bionic *
Python2.7 Ubuntu esm-infra/xenial *
Python2.7 Ubuntu focal *
Python2.7 Ubuntu jammy *
Python2.7 Ubuntu kinetic *
Python2.7 Ubuntu precise/esm *
Python2.7 Ubuntu trusty *
Python2.7 Ubuntu trusty/esm *
Python2.7 Ubuntu vivid/ubuntu-core *
Python2.7 Ubuntu xenial *
Python3.10 Ubuntu devel *
Python3.10 Ubuntu jammy *
Python3.10 Ubuntu kinetic *
Python3.10 Ubuntu trusty *
Python3.10 Ubuntu xenial *
Python3.4 Ubuntu esm-infra-legacy/trusty *
Python3.4 Ubuntu trusty *
Python3.4 Ubuntu trusty/esm *
Python3.4 Ubuntu vivid/stable-phone-overlay *
Python3.4 Ubuntu vivid/ubuntu-core *
Python3.4 Ubuntu xenial *
Python3.5 Ubuntu esm-infra-legacy/trusty *
Python3.5 Ubuntu esm-infra/xenial *
Python3.5 Ubuntu trusty *
Python3.5 Ubuntu trusty/esm *
Python3.5 Ubuntu xenial *
Python3.6 Ubuntu bionic *
Python3.6 Ubuntu esm-infra/bionic *
Python3.6 Ubuntu trusty *
Python3.6 Ubuntu xenial *
Python3.7 Ubuntu bionic *
Python3.7 Ubuntu esm-apps/bionic *
Python3.7 Ubuntu trusty *
Python3.7 Ubuntu xenial *
Python3.8 Ubuntu bionic *
Python3.8 Ubuntu esm-apps/bionic *
Python3.8 Ubuntu focal *
Python3.8 Ubuntu trusty *
Python3.8 Ubuntu xenial *
Python3.9 Ubuntu esm-apps/focal *
Python3.9 Ubuntu focal *
Python3.9 Ubuntu trusty *
Python3.9 Ubuntu xenial *
Red Hat Enterprise Linux 8 RedHat python3-0:3.6.8-48.el8_7.1 *
Red Hat Enterprise Linux 8 RedHat python38:3.8-8080020221221151857.0d9ba776 *
Red Hat Enterprise Linux 8 RedHat python38-devel:3.8-8080020221221151857.0d9ba776 *
Red Hat Enterprise Linux 8 RedHat python39:3.9-8080020221221152015.aed85c85 *
Red Hat Enterprise Linux 8 RedHat python39-devel:3.9-8080020221221152015.aed85c85 *
Red Hat Enterprise Linux 8 RedHat python39:3.9-8080020221221152015.aed85c85 *
Red Hat Enterprise Linux 8 RedHat python39-devel:3.9-8080020221221152015.aed85c85 *
Red Hat Enterprise Linux 8 RedHat python3-0:3.6.8-48.el8_7.1 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat python3-0:3.6.8-47.el8_6.4 *
Red Hat Enterprise Linux 9 RedHat python3.9-0:3.9.10-3.el9_0 *
Red Hat Enterprise Linux 9 RedHat python3.9-0:3.9.10-3.el9_0 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-python38-python-0:3.8.14-1.el7 *

References