Vulnerability Description
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Python | Python | >= 2.7.0, < 2.7.15 |
| Fedoraproject | Fedora | 28 |
| Canonical | Ubuntu Linux | 12.04 |
| Redhat | Ansible Tower | 3.3 |
| Redhat | Enterprise Linux Desktop | 7.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Workstation | 7.0 |
| Debian | Debian Linux | 8.0 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.htmlMailing ListThird Party Advisory
- http://www.securitytracker.com/id/1042001Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHBA-2019:0327Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1260Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3725Third Party Advisory
- https://bugs.python.org/issue32981ExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1060Issue TrackingThird Party Advisory
- https://docs.python.org/3.5/whatsnew/changelog.html#python-3-5-6-release-candidaProductVendor Advisory
- https://docs.python.org/3.6/whatsnew/changelog.html#python-3-6-5-release-candidaProductVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00030.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00031.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2018-1060?
CVE-2018-1060 is a vulnerability with a CVSS score of 7.5 (HIGH). python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
How severe is CVE-2018-1060?
CVE-2018-1060 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-1060?
Check the references section above for vendor advisories and patch information. Affected products include: Python Python, Fedoraproject Fedora, Canonical Ubuntu Linux, Redhat Ansible Tower, Redhat Enterprise Linux Desktop.