Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000117

Опубликовано: 07 мар. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.2
CVSS3: 6.7

Описание

Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.

РелизСтатусПримечание
artful

DNE

bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

not-affected

windows only
esm-infra/focal

DNE

focal

DNE

groovy

DNE

hirsute

DNE

Показывать по

РелизСтатусПримечание
artful

DNE

bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

not-affected

windows only
esm-infra/focal

DNE

esm-infra/xenial

not-affected

windows only
focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

windows only
bionic

not-affected

windows only
devel

DNE

disco

DNE

eoan

DNE

esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

windows only
esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

РелизСтатусПримечание
artful

not-affected

windows only
bionic

not-affected

windows only
devel

DNE

disco

not-affected

windows only
eoan

not-affected

windows only
esm-apps/bionic

not-affected

windows only
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

EPSS

Процентиль: 19%
0.00059
Низкий

7.2 High

CVSS2

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
больше 7 лет назад

Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.

CVSS3: 6.7
debian
больше 7 лет назад

Python Software Foundation CPython version From 3.2 until 3.6.4 on Win ...

CVSS3: 6.7
github
около 3 лет назад

Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.

EPSS

Процентиль: 19%
0.00059
Низкий

7.2 High

CVSS2

6.7 Medium

CVSS3

Уязвимость CVE-2018-1000117