Candidate: CVE-2021-40839 PublicDate: 2021-09-10 02:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-40839 https://github.com/aresch/rencode/commit/572ff74586d9b1daab904c6f7f7009ce0143bb75 https://github.com/aresch/rencode/pull/29 https://pypi.org/project/rencode/#history https://seclists.org/fulldisclosure/2021/Sep/16 Description: The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_python-rencode: upstream_python-rencode: released (1.0.6-2) trusty_python-rencode: ignored (out of standard support) trusty/esm_python-rencode: DNE xenial_python-rencode: ignored (out of standard support) bionic_python-rencode: needs-triage focal_python-rencode: needs-triage hirsute_python-rencode: ignored (reached end-of-life) impish_python-rencode: needs-triage jammy_python-rencode: needs-triage devel_python-rencode: needs-triage