ZeroHour

CVE-2018-14647

CVSS 3.1
7.5 high
EPSS
11%p96
Published
()
Modified
Description

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.

Vendors
pythoncanonicaldebianfedoraprojectopensuseredhat
Products
python, ubuntu linux, debian linux, fedora, leap, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-335, CWE-665, CWE-909
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.