CVE-2018-1060
🟡 Monitoruj
Katastrofalne cofanie w pop3lib w Pythonie prowadzi do odmowy usługi.
CVSS
7.5
EPSS
5.0%
Exploit
poc
Vendor
canonical
Opis źródłowy (NVD)
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 5.0% |
| Opublikowano (NVD) | 2018-06-18 14:29:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 21:17:08 UTC |
Referencje
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html ([email protected]) [Mailing List, Third Party Advisory]
- http://www.securitytracker.com/id/1042001 ([email protected]) [Third Party Advisory, VDB Entry]
- https://access.redhat.com/errata/RHBA-2019:0327 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:3041 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2018:3505 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:1260 ([email protected]) [Third Party Advisory]
- https://access.redhat.com/errata/RHSA-2019:3725 ([email protected]) [Third Party Advisory]
- https://bugs.python.org/issue32981 ([email protected]) [Exploit, Issue Tracking, Vendor Advisory]
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1060 ([email protected]) [Issue Tracking, Third Party Advisory]
- https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-6-release-candidate-1 ([email protected]) [Product, Vendor Advisory]
- https://docs.python.org/3.6/whatsnew/changelog.html#python-3-6-5-release-candidate-1 ([email protected]) [Product, Vendor Advisory]
- https://lists.debian.org/debian-lts-announce/2018/09/msg00030.html ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2018/09/msg00031.html ([email protected]) [Mailing List, Third Party Advisory]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/ ([email protected])
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/ ([email protected])
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/ ([email protected])
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03951en_us ([email protected]) [Third Party Advisory]
- https://usn.ubuntu.com/3817-1/ ([email protected]) [Third Party Advisory]
- https://usn.ubuntu.com/3817-2/ ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2018/dsa-4306 ([email protected]) [Third Party Advisory]
- https://www.debian.org/security/2018/dsa-4307 ([email protected]) [Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujan2020.html ([email protected]) [Third Party Advisory]