FlawAtlas
Search the atlas
SUSE-SU-2018:3156-1 Not scored

Security update for python

This update for python fixes the following issue: - CVE-2018-14647: Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM (bsc#1109847)

Exploit probability Not scored
Published October 16, 2018
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 11 SP4 python
SUSE:Linux Enterprise Server 11 SP4 python-base
SUSE:Linux Enterprise Server 11 SP4 python-doc
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 python
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 python-base
SUSE:Linux Enterprise Server for SAP Applications 11 SP4 python-doc
SUSE:Linux Enterprise Software Development Kit 11 SP4 python
SUSE:Linux Enterprise Software Development Kit 11 SP4 python-base
SUSE:Linux Enterprise Software Development Kit 11 SP4 python-doc

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2018:3156-1

This update for python fixes the following issue: - CVE-2018-14647: Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM (bsc#1109847)

View original source

05 / REFERENCES

Further evidence