CVE-2018-1000030 describes Heap-Buffer-Overflow and Heap-Use-After-Free vulnerabilities in Python 2.7.14 and potentially earlier versions, affecting canonical python and ubuntu_linux distributions. These race condition vulnerabilities occur when multiple threads handle large amounts of data, leading to memory corruption. The vulnerability has a CVSSv3.1 score of 3.6 (Low), indicating a local attack vector, high attack complexity, and low impact on confidentiality and availability. While the Python Security Response Team (PSRT) does not consider it a security vulnerability due to the requirement for attacker-controlled code execution, it could violate trust boundaries in environments like Function-as-a-Service. There is no evidence of active exploitation, nor is exploit code available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community attention, with no social media discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7.14CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
12.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.