CVE-2018-1000117
07.03.2018, 14:29
Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.
Vendor | Product | Version |
---|---|---|
python | python | 3.2.0 ≤ 𝑥 < 3.4.9 |
python | python | 3.5.0 ≤ 𝑥 < 3.5.6 |
python | python | 3.6.0 ≤ 𝑥 < 3.6.5 |
python | python | 3.7.0:beta1 |
python | python | 3.7.0:beta2 |
python | python | 3.7.0:beta3 |
python | python | 3.7.0:beta4 |
python | python | 3.7.0:beta5 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python3.4 |
| ||||||||||||||||||||||||||
python3.5 |
| ||||||||||||||||||||||||||
python3.6 |
| ||||||||||||||||||||||||||
python3.7 |
|