CVE-2018-14647

HIGH

Python <3.7.0-2.7.15 - DoS

Title source: llm
STIX 2.1

Description

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.

Scores

CVSS v3 7.5
EPSS 0.0125
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-909 CWE-665 CWE-335
Status published
Products (13)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
debian/debian_linux 8.0
debian/debian_linux 9.0
fedoraproject/fedora 30
opensuse/leap 15.1
python/python 3.7.0
python/python 2.7.0 - 2.7.15
... and 3 more
Published Sep 25, 2018
Tracked Since Feb 18, 2026