CVE-2018-1060
EUVD-2018-1171318.06.2018, 14:29
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | python | 2.7.0 ≤ 𝑥 < 2.7.15 |
| python | python | 3.0.0 ≤ 𝑥 < 3.4.9 |
| python | python | 3.5.0 ≤ 𝑥 < 3.5.6 |
| python | python | 3.6.0 < 𝑥 < 3.6.5 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| redhat | ansible_tower | 3.3 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python2.7 |
| ||||||||||||||||||||||||||||||||
| python3.4 |
| ||||||||||||||||||||||||||||||||
| python3.5 |
| ||||||||||||||||||||||||||||||||
| python3.6 |
| ||||||||||||||||||||||||||||||||
| python3.7 |
|
Common Weakness Enumeration
References