FlawAtlas
Search the atlas
SUSE-SU-2018:2408-1 Not scored

Security update for python

This update for python-base fixes the following issues: Security issues fixed: - CVE-2018-1061: Fixed DoS via regular expression backtracking in difflib.IS_LINE_JUNK method in difflib (bsc#1088004). - CVE-2018-1060: Fixed DoS via regular expression catastrophic backtracking in apop() method in pop3lib (bsc#1088009). - CVE-2016-5636: Fixed heap overflow in zipimporter module (bsc#985177) Bug fixes: - bsc#1086001: python tarfile uses random order.

Exploit probability Not scored
Published August 17, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Point of Sale 11 SP3 python
SUSE:Linux Enterprise Point of Sale 11 SP3 python-base
SUSE:Linux Enterprise Point of Sale 11 SP3 python-doc
SUSE:Linux Enterprise Server 11 SP3-LTSS python
SUSE:Linux Enterprise Server 11 SP3-LTSS python-base
SUSE:Linux Enterprise Server 11 SP3-LTSS python-doc
SUSE:Linux Enterprise Server 11 SP3-TERADATA python
SUSE:Linux Enterprise Server 11 SP3-TERADATA python-base
SUSE:Linux Enterprise Server 11 SP3-TERADATA python-doc
SUSE:Linux Enterprise Server 11 SP4 python
SUSE:Linux Enterprise Server 11 SP4 python-base
SUSE:Linux Enterprise Server 11 SP4 python-doc
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 python
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 python-base
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 python-doc
SUSE:Linux Enterprise Software Development Kit 11 SP4 python
SUSE:Linux Enterprise Software Development Kit 11 SP4 python-base
SUSE:Linux Enterprise Software Development Kit 11 SP4 python-doc

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:2408-1

This update for python-base fixes the following issues: Security issues fixed: - CVE-2018-1061: Fixed DoS via regular expression backtracking in difflib.IS_LINE_JUNK method in difflib (bsc#1088004). - CVE-2018-1060: Fixed DoS via regular expression catastrophic backtracking in apop() method in pop3lib (bsc#1088009). - CVE-2016-5636: Fixed heap overflow in zipimporter module (bsc#985177) Bug fixes: - bsc#1086001: python tarfile uses random order.

View original source

05 / REFERENCES

Further evidence