Skip to content
appaloosa scout logo main rounded
MEDIUM 6.5

CVE-2018-1061

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.

CVSS v3 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS 1.8% percentile 82.9%

Affected tracked apps

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
python python Windows <2.7.15 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.0 <3.4.9 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.5.0 ≤3.5.5 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows ≥3.6 ≤3.6.4 cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:alpha1:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:alpha2:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:alpha3:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:alpha4:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta1:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta2:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta3:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta4:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:beta5:*:*:*:*:*:*
python python Windows cpe:2.3:a:python:python:3.7.0:rc1:*:*:*:*:*:*
View on NVD ↗