← לוח פגיעויות

CVE-2018-14647

גבוהה 7.5

תיאור (מקור, אנגלית)

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
11% (אחוזון 100) נכון ל-8/10/2026
CWE
CWE-335, CWE-665, CWE-909

מוצרים מושפעים

python: python; canonical: ubuntu linux; debian: debian linux; fedoraproject: fedora; opensuse: leap; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation

קישורים