Arbitrary Command Injection

Affecting python2.7 package, versions <2.7.13-2+deb9u3

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

References

CVSS Score

9.8
high severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    High
  • Integrity
    High
  • Availability
    High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE
CVE-2018-1000802
CWE
CWE-77
Snyk ID
SNYK-DEBIAN9-PYTHON27-306503
Disclosed
18 Sep, 2018
Published
25 Sep, 2018