The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
| Software | From | Fixed in |
|---|---|---|
| rencode_project / rencode | - | 1.0.6.x |
| fedoraproject / fedora | 34 | 34.x |
| fedoraproject / fedora | 35 | 35.x |
rencode
|
- | 1.0.6.x |