ISOMAN

CVE

CVE-2018-14647

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
  2. http://www.securityfocus.com/bid/105396
  3. http://www.securitytracker.com/id/1041740
  4. https://access.redhat.com/errata/RHSA-2019:1260
  5. https://access.redhat.com/errata/RHSA-2019:2030
  6. https://access.redhat.com/errata/RHSA-2019:3725
  7. https://bugs.python.org/issue34623
  8. https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14647
  9. https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
  10. https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html
  11. https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html
  12. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBJCB2HWOJLP3L7CUQHJHNBHLSVOXJE5/
  13. https://usn.ubuntu.com/3817-1/
  14. https://usn.ubuntu.com/3817-2/
  15. https://www.debian.org/security/2018/dsa-4306
  16. https://www.debian.org/security/2018/dsa-4307
  17. http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
  18. http://www.securityfocus.com/bid/105396
  19. http://www.securitytracker.com/id/1041740
  20. https://access.redhat.com/errata/RHSA-2019:1260