CVE-2025-13837

Updated: 2026-02-04 05:06:57.501916

Description:

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Debian 12 python 3.6 5.5 MEDIUM Released CLSA-2026:1771327791 2026-02-17 15:48:55
Debian 12 python 2.7 5.5 MEDIUM Needs Triage 2026-02-04 09:00:23
Debian 12 python 3.8 5.5 MEDIUM Released CLSA-2026:1771328775 2026-02-17 15:48:30
Debian 13 python 3.9 5.5 MEDIUM Released CLSA-2026:1771343841 2026-02-17 18:17:53
Debian 13 python 3.6 5.5 MEDIUM Released CLSA-2026:1771328334 2026-02-17 15:48:51
Debian 13 python 2.7 5.5 MEDIUM Needs Triage 2026-02-04 09:00:13
Debian 13 python 3.8 5.5 MEDIUM Released CLSA-2026:1771328555 2026-02-17 15:48:32
Debian 13 python 3.7 5.5 MEDIUM Released CLSA-2026:1771329219 2026-02-17 15:48:33
EL 10 python 2.7 5.5 MEDIUM Needs Triage 2026-02-04 09:00:03
EL 10 python 3.6 5.5 MEDIUM Released CLSA-2026:1771342507 2026-02-17 15:49:00
Total: 36