VulnerabilityModified
CVE-2018-1060
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method.
HIGH 7.5EPSS 5.04%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 5.04% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- python/python · fedoraproject/fedora · canonical/ubuntu linux · redhat/ansible tower · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation · debian/debian linux
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlMailing List, Third Party Advisory
- http://www.securitytracker.com/id/1042001Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3725Third Party Advisory
- https://bugs.python.org/issue32981Exploit, Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1060Issue Tracking, Third Party Advisory
- https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-6-release-candidate-1Product, Vendor Advisory
- https://docs.python.org/3.6/whatsnew/changelog.html#python-3-6-5-release-candidate-1Product, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00030.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00031.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03951en_usThird Party Advisory
- https://usn.ubuntu.com/3817-1/Third Party Advisory
- https://usn.ubuntu.com/3817-2/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4306Third Party Advisory
- https://www.debian.org/security/2018/dsa-4307Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlMailing List, Third Party Advisory
- http://www.securitytracker.com/id/1042001Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3725Third Party Advisory
- https://bugs.python.org/issue32981Exploit, Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.