SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-14647

This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM.

HIGH 7.5EPSS 10.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 10.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
10.91% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-335, CWE-665, CWE-909
Affected
python/python · canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora · opensuse/leap · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux workstation
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.