CVE-2012-1150

Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Date published : 2012-10-05

http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html

http://bugs.python.org/issue13703