CVE-2018-1000802

    Dashboard / Vulnerabilities / CVE-2018-1000802

    CVE-2018-1000802

    Published: 18 Sept 2018Last Modified: 7 Aug 2026

    Summary:

    Details: Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v2.7.16rc1
    v2.7.15rc1
    v2.7.13rc1
    v2.7.12rc1
    v2.7.11rc1
    v2.7.10rc1
    v2.7.9rc1
    v2.7.8
    v2.7.6rc1
    v2.7.5
    v2.7.4rc1
    v2.7.3rc1
    v2.7.2rc1
    v2.7
    v2.7.1
    v2.7.1rc1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High