CVE-2018-1061
19.06.2018, 12:29
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.Enginsight
| Vendor | Product | Version |
|---|---|---|
| python | python | 𝑥 < 2.7.15 |
| python | python | 3.0 ≤ 𝑥 < 3.4.9 |
| python | python | 3.5.0 ≤ 𝑥 ≤ 3.5.5 |
| python | python | 3.6 ≤ 𝑥 ≤ 3.6.4 |
| python | python | 3.7.0:alpha1 |
| python | python | 3.7.0:alpha2 |
| python | python | 3.7.0:alpha3 |
| python | python | 3.7.0:alpha4 |
| python | python | 3.7.0:beta1 |
| python | python | 3.7.0:beta2 |
| python | python | 3.7.0:beta3 |
| python | python | 3.7.0:beta4 |
| python | python | 3.7.0:beta5 |
| python | python | 3.7.0:rc1 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| redhat | ansible_tower | 3.3 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python2.7 |
| ||||||||||||||||||||||||||||||||
| python3.4 |
| ||||||||||||||||||||||||||||||||
| python3.5 |
| ||||||||||||||||||||||||||||||||
| python3.6 |
| ||||||||||||||||||||||||||||||||
| python3.7 |
|
Common Weakness Enumeration
References