Skip to content
appaloosa scout logo main rounded
HIGH 7.5

CVE-2018-1060

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS 1.0% percentile 77.6%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
python python Windows ≥2.7.0 <2.7.15 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.0.0 <3.4.9 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.5.0 <3.5.6 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows >3.6.0 <3.6.5 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
View on NVD ↗