CVE-2018-14647
This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 10.91% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-335, CWE-665, CWE-909
- Affected
- python/python · canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora · opensuse/leap · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105396Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041740Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2030Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3725Third Party Advisory
- https://bugs.python.org/issue34623Issue Tracking, Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14647Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/06/msg00022.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00023.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBJCB2HWOJLP3L7CUQHJHNBHLSVOXJE5/
- https://usn.ubuntu.com/3817-1/Third Party Advisory
- https://usn.ubuntu.com/3817-2/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4306Third Party Advisory
- https://www.debian.org/security/2018/dsa-4307Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlMailing List, Third Party Advisory
- http://www.securityfocus.com/bid/105396Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041740Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2030Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3725Third Party Advisory
- https://bugs.python.org/issue34623Issue Tracking, Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14647Issue Tracking, Third Party Advisory
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2019/06/msg00022.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/06/msg00023.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBJCB2HWOJLP3L7CUQHJHNBHLSVOXJE5/
- https://usn.ubuntu.com/3817-1/Third Party Advisory
- https://usn.ubuntu.com/3817-2/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.