First published: Tue Sep 18 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/python2.7 | 2.7.18-8+deb11u1 | |
Python 2.7 | >=2.7.0<2.7.16 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 | |
SUSE Linux | =15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000802 is considered a medium-severity vulnerability that can lead to command injection and denial of service.
To fix CVE-2018-1000802, update Python to version 2.7.18 or later where the vulnerability has been patched.
CVE-2018-1000802 affects all versions of Python 2.7 up to 2.7.16.
Yes, CVE-2018-1000802 can potentially lead to information disclosure through command injection vulnerabilities.
The vulnerability in CVE-2018-1000802 is located in the shutil module, specifically the make_archive function.