CVE-2018-1000802

CRITICAL

Python Software Foundation Python <2.7 - Command Injection

Title source: llm

Description

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

Exploits (1)

nomisec WORKING POC 4 stars
by tna0y · poc
https://github.com/tna0y/CVE-2018-1000802-PoC

Scores

CVSS v3 9.8
EPSS 0.2745
EPSS Percentile 96.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-77
Status published

Affected Products (8)

python/python < 2.7.16
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
opensuse/leap

Timeline

Published Sep 18, 2018
Tracked Since Feb 18, 2026