CVE-2018-1000802
Summary
| CVE | CVE-2018-1000802 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-18 17:29:00 UTC |
| Updated | 2023-11-07 02:51:00 UTC |
| Description | Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Application | Python | Python | All | All | All | All |
| Application | Python | Python | 2.7.0 | All | All | All |
| Application | Python | Python | 2.7.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| MEGA | MISC | mega.nz | Exploit, Third Party Advisory |
| [SECURITY] [DLA 1520-1] python3.4 security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4306-1 python2.7 | DEBIAN | www.debian.org | Third Party Advisory |
| MEGA | mega.nz | ||
| [security-announce] openSUSE-SU-2020:0086-1: important: Security update | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| Issue 34540: shutil._call_external_zip should use subprocess - Python tracker | CONFIRM | bugs.python.org | Issue Tracking, Patch, Vendor Advisory |
| USN-3817-1: Python vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| USN-3817-2: Python vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| [2.7] closes bpo-34540: Convert shutil._call_external_zip to use subprocess rather than distutils.spawn. by benjaminp · Pull Request #8985 · python/cpython · GitHub | CONFIRM | github.com | Patch, Vendor Advisory |
| [SECURITY] [DLA 1519-1] python2.7 security update | MLIST | lists.debian.org | Mailing List, Third Party Advisory |
| CVE-2018-1000802 Python Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| [2.7] closes bpo-34540: Convert shutil._call_external_zip to use subprocess rather than distutils.spawn. by benjaminp · Pull Request #8985 · python/cpython · GitHub | CONFIRM | github.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.