Python CVE-2018-1000802 Remote Command Injection Vulnerability
BID:107308
Info
Python CVE-2018-1000802 Remote Command Injection Vulnerability
| Bugtraq ID: | 107308 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-1000802 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 18 2018 12:00AM |
| Updated: | Sep 18 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 18.04 LTS Ubuntu Ubuntu Linux 16.04 LTS Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 ESM Python Software Foundation Python 2.7 |
| Not Vulnerable: | |
Exploit / POC
Python CVE-2018-1000802 Remote Command Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Python CVE-2018-1000802 Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Python CVE-2018-1000802 Remote Command Injection Vulnerability
References:
References:
- closes bpo-34540: Convert shutil._call_external_zip to use subprocess (Python)
- closes bpo-34540: Convert shutil._call_external_zip to use subprocess rath (Python)
- shutil._call_external_zip should use subprocess (Python)
- Bug 1631420 CVE-2018-1000802 python: Command injection in the shutil module (Redhat)
- CVE-2018-1000802 (Redhat)
- DSA-4306-1 python2.7 -- security update (Debian)
- USN-3817-1: Python vulnerabilities (Ubuntu)
- USN-3817-2: Python vulnerabilities (Ubuntu)