Red Hat Bugzilla – Bug 1549192
CVE-2018-1061 python: DOS via regular expression backtracking in difflib.IS_LINE_JUNK method in difflib
Last modified: 2018-10-30 03:24:41 EDT
Catastrophic backtracking vulnerability was found in Python. Exploitation of a regular expression in difflib.IS_LINE_JUNK method in servers that use difflib can lead to denial of service. Upstream issue: https://bugs.python.org/issue32981
Created python3 tracking bugs for this issue: Affects: fedora-all [bug 1563462] Created python26 tracking bugs for this issue: Affects: fedora-all [bug 1563464] Created python33 tracking bugs for this issue: Affects: fedora-all [bug 1563465] Created python34 tracking bugs for this issue: Affects: fedora-all [bug 1563463] Created python35 tracking bugs for this issue: Affects: fedora-all [bug 1563461]
External References: https://docs.python.org/3.6/whatsnew/changelog.html#python-3-6-5-final
Acknowledgments: Name: the Python security response team
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2018:3041 https://access.redhat.com/errata/RHSA-2018:3041