Back
CVE-2018-1000802
CRITICAL
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.
Published: Sep 18, 2018
Modified: Jun 17, 2026
CWE-77
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| python | python | * ≥ 2.7.0 < 2.7.16 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| opensuse | leap | 15.1 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| opensuse | leap | 15.1 |
GitHub Security Advisory GHSA-grfr-pqc4-fqmw
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper...
References (22)
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html Mailing List, Third Party Advisory
- https://bugs.python.org/issue34540 Issue Tracking, Patch, Vendor Advisory
- https://github.com/python/cpython/pull/8985 Patch, Vendor Advisory
- https://github.com/python/cpython/pull/8985/commits/add531a1e55b0a739b0f42582f1c9747e5649ace Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00030.html Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/09/msg00031.html Mailing List, Third Party Advisory
- https://mega.nz/#%21JUFiCC4R%21mq-jQ8ySFwIhX6WMDujaZuNBfttDVt7DETlfOIQE1ig
- https://security.netapp.com/advisory/ntap-20230309-0002/
- https://usn.ubuntu.com/3817-1/ Third Party Advisory
- https://usn.ubuntu.com/3817-2/ Third Party Advisory
- https://www.debian.org/security/2018/dsa-4306 Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html Mailing List, Third Party Advisory
- https://bugs.python.org/issue34540 Issue Tracking, Patch, Vendor Advisory
- https://github.com/python/cpython/pull/8985 Patch, Vendor Advisory
- https://github.com/python/cpython/pull/8985/commits/add531a1e55b0a739b0f42582f1c9747e5649ace Patch, Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
20.81%
Top 3% most likely to be exploited
Threat Score
45.4 / 100
Data Sources
NVD
EPSS
GitHub