Aller au contenu
appaloosa scout logo main rounded
MEDIUM 6.7

CVE-2018-1000117

EN Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.

CVSS v3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS 0.1% percentile 15.9%

Apps suivies affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
python python Windows ≥3.2.0 <3.4.9 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.5.0 <3.5.6 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.6.0 <3.6.5 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta1:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta2:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta3:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta4:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta5:*:*:*:*:*:*
Voir sur NVD ↗