CVE-2018-1061Improper Input Validation in Python

Severity
7.5HIGHNVD
CNA6.5
EPSS
1.5%
top 19.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 19
Latest updateJul 11

Description

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Also affects: Debian Linux 8.0, 9.0, Fedora 28, 29, 30, Ubuntu Linux 12.04, 14.04, 16.04, 18.04

🔴Vulnerability Details

4
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities2024-07-11
GHSA
GHSA-gf62-w85x-fjpv: python before versions 22022-05-13
CVEList
CVE-2018-1061: python before versions 22018-06-19
OSV
CVE-2018-1061: python before versions 22018-06-19

📋Vendor Advisories

5
Ubuntu
Python vulnerabilities2024-07-11
Ubuntu
Python vulnerabilities2018-11-15
Ubuntu
Python vulnerabilities2018-11-13
Red Hat
python: DOS via regular expression backtracking in difflib.IS_LINE_JUNK method in difflib2018-03-14
Debian
CVE-2018-1061: python2.7 - python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable...2018

💬Community

6
Bugzilla
CVE-2018-1060 CVE-2018-1061 python34: various flaws [fedora-all]2018-04-04
Bugzilla
CVE-2018-1060 CVE-2018-1061 python26: various flaws [fedora-all]2018-04-04
Bugzilla
CVE-2018-1060 CVE-2018-1061 python33: various flaws [fedora-all]2018-04-04
Bugzilla
CVE-2018-1060 CVE-2018-1061 python3: various flaws [fedora-all]2018-04-04
Bugzilla
CVE-2018-1060 CVE-2018-1061 python35: various flaws [fedora-all]2018-04-04
CVE-2018-1061 — Improper Input Validation in Python | cvebase