CVE-2018-14647
גבוהה 7.5
תיאור (מקור, אנגלית)
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 11% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-335, CWE-665, CWE-909
מוצרים מושפעים
python: python; canonical: ubuntu linux; debian: debian linux; fedoraproject: fedora; opensuse: leap; redhat: enterprise linux desktop; redhat: enterprise linux server; redhat: enterprise linux workstation
קישורים
- https://bugs.python.org/issue34623 Issue TrackingPatchVendor Advisory
- https://bugs.python.org/issue34623 Issue TrackingPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html Mailing ListThird Party Advisory
- http://www.securityfocus.com/bid/105396 Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041740 Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:1260 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2030 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3725 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14647 Issue TrackingThird Party Advisory
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334…