ISOMAN

CVE

CVE-2018-1060

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
  2. http://www.securitytracker.com/id/1042001
  3. https://access.redhat.com/errata/RHBA-2019:0327
  4. https://access.redhat.com/errata/RHSA-2018:3041
  5. https://access.redhat.com/errata/RHSA-2018:3505
  6. https://access.redhat.com/errata/RHSA-2019:1260
  7. https://access.redhat.com/errata/RHSA-2019:3725
  8. https://bugs.python.org/issue32981
  9. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1060
  10. https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-6-release-candidate-1
  11. https://docs.python.org/3.6/whatsnew/changelog.html#python-3-6-5-release-candidate-1
  12. https://lists.debian.org/debian-lts-announce/2018/09/msg00030.html
  13. https://lists.debian.org/debian-lts-announce/2018/09/msg00031.html
  14. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/46PVWY5LFP4BRPG3BVQ5QEEFYBVEXHCK/
  15. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AEZ5IQT7OF7Q2NCGIVABOWYGKO7YU3NJ/
  16. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JSKPGPZQNTAULHW4UH63KGOOUIDE4RRB/
  17. https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst03951en_us
  18. https://usn.ubuntu.com/3817-1/
  19. https://usn.ubuntu.com/3817-2/
  20. https://www.debian.org/security/2018/dsa-4306