SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19275

typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read.

HIGH 7.5EPSS 3.28%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

typed_ast 1.3.0 and 1.3.1 has an ast_for_arguments out-of-bounds read. An attacker with the ability to cause a Python interpreter to parse Python source (but not necessarily execute it) may be able to crash the interpreter process. This could be a concern, for example, in a web-based service that parses (but does not execute) Python code. (This issue also affected certain Python 3.8.0-alpha prereleases.)

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
3.28% probability · 88th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
python/typed ast
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.