ALPINE-CVE-2018-1060 PUBLISHED CVSS 7.5 HIGH

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.9python22.6.5-r7, 2.7.14-r3, 2.7.3-r5
Alpine:v3.6python22.7.7-r0, 2.7.11-r1, 2.7.6-r4
Alpine:v3.12python22.7.9-r2, 2.7.9-r1, 2.7.10-r1
Alpine:v3.10python22.6.1-r1, 2.7.3-r5, 2.7.3-r4
Alpine:v3.8python33.3.2-r0, 3.3.0-r0, 3.2.3-r0
Alpine:v3.5python22.6.1-r0, 0, 2.6.1-r0
Alpine:v3.7python22.7.8-r0, 2.7.6-r4, 2.7.6-r2
Alpine:v3.6python30, 3.1.3-r0, 3.2.0-r0
Alpine:v3.5python30, 3.1.3-r0, 3.3.0-r0
Alpine:v3.11python22.7.6-r3, 2.7.14-r4, 0
Alpine:v3.7python33.1.3-r0, 3.2.0-r0, 3.2.3-r0

Timeline

References

Open in Interactive Console →