Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 676706 (CVE-2018-1061)

Summary: <dev-lang/python-{2.7.15,3.4.9,3.5.6,3.7.0}: DoS in difflib.IS_LINE_JUNK
Product: Gentoo Security Reporter: psp <gentoo-bugzilla>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: A4 [noglsa cve]
Package list:
Runtime testing required: ---

Description psp 2019-01-29 08:41:08 UTC
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.

$ wget -q

$ python3 --version
Python 3.4.8
$ python3.5 --version
Python 3.5.5

$ python3
test_is_character_junk_false (__main__.TestJunkAPIs) ... ok
test_is_character_junk_true (__main__.TestJunkAPIs) ... ok
test_is_line_junk_REDOS (__main__.TestJunkAPIs) ... 

The currently-shipped Python 3.6.5 appears to not be affected.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2019-03-27 02:59:36 UTC
dev-lang/python-3.4* is masked for removal due to being EOL.