Python's elementtree C accelerator failed to initialise Expat's hash salt...
Vulnerability Description
Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-14647
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.debian.org/security/2018/dsa-4306
- https://usn.ubuntu.com/3817-2/
- http://www.securitytracker.com/id/1041740
- http://www.securityfocus.com/bid/105396
- https://www.debian.org/security/2018/dsa-4307
- https://bugs.python.org/issue34623
- https://usn.ubuntu.com/3817-1/
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14647
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RBJCB2HWOJLP3L7CUQHJHNBHLSVOXJE5/
- https://access.redhat.com/errata/RHSA-2019:1260
- https://lists.debian.org/debian-lts-announce/2019/06/msg00022.html
- https://lists.debian.org/debian-lts-announce/2019/06/msg00023.html
- https://access.redhat.com/errata/RHSA-2019:2030
- https://access.redhat.com/errata/RHSA-2019:3725
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
- https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3E
Affected Vendor
The Python Project
View all reports →Affected Software
Timeline
CVSS Vectors
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.