Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000802

Опубликовано: 18 сент. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 9.8

Описание

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

РелизСтатусПримечание
bionic

released

2.7.15~rc1-1ubuntu0.1
cosmic

not-affected

2.7.15-4ubuntu4
devel

not-affected

2.7.15-4ubuntu4
esm-infra-legacy/trusty

not-affected

2.7.6-8ubuntu0.5
esm-infra/bionic

not-affected

2.7.15~rc1-1ubuntu0.1
esm-infra/xenial

not-affected

2.7.12-1ubuntu0~16.04.4
precise/esm

not-affected

2.7.3-0ubuntu3.11
trusty

released

2.7.6-8ubuntu0.5
trusty/esm

not-affected

2.7.6-8ubuntu0.5
upstream

needs-triage

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

not-affected

3.4.3-1ubuntu1~14.04.7
precise/esm

DNE

trusty

released

3.4.3-1ubuntu1~14.04.7
trusty/esm

not-affected

3.4.3-1ubuntu1~14.04.7
upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

esm-infra-legacy/trusty

not-affected

code present
esm-infra/xenial

not-affected

code present
precise/esm

DNE

trusty

not-affected

code present
trusty/esm

not-affected

code present
upstream

needs-triage

xenial

not-affected

code present

Показывать по

РелизСтатусПримечание
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

code not present
esm-infra-legacy/trusty

DNE

esm-infra/bionic

not-affected

code not present
precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

code not present
cosmic

not-affected

code not present
devel

not-affected

code not present
esm-apps/bionic

not-affected

code not present
esm-infra-legacy/trusty

DNE

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

needs-triage

xenial

DNE

Показывать по

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
почти 7 лет назад

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

CVSS3: 9.8
nvd
почти 7 лет назад

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

CVSS3: 9.8
debian
почти 7 лет назад

Python Software Foundation Python (CPython) version 2.7 contains a CWE ...

suse-cvrf
больше 6 лет назад

Security update for python

suse-cvrf
больше 6 лет назад

Security update for python

7.5 High

CVSS2

9.8 Critical

CVSS3

Уязвимость CVE-2018-1000802