ALAS-2018-1108

Related Vulnerabilities: CVE-2018-1060   CVE-2018-1061  

A flaw was found in the way catastrophic backtracking was implemented in python's pop3lib's apop() method. An attacker could use this flaw to cause denial of service.(CVE-2018-1060) A flaw was found in the way catastrophic backtracking was implemented in python's difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.(CVE-2018-1061)

ALAS-2018-1108


Amazon Linux AMI Security Advisory: ALAS-2018-1108
Advisory Release Date: 2018-12-06 00:22 Pacific
Advisory Updated Date: 2018-12-07 00:46 Pacific
Severity: Medium

Issue Overview:

A flaw was found in the way catastrophic backtracking was implemented in python's pop3lib's apop() method. An attacker could use this flaw to cause denial of service.(CVE-2018-1060)

A flaw was found in the way catastrophic backtracking was implemented in python's difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service.(CVE-2018-1061)


Affected Packages:

python27


Issue Correction:
Run yum update python27 to update your system.

New Packages:
i686:
    python27-libs-2.7.15-1.124.amzn1.i686
    python27-debuginfo-2.7.15-1.124.amzn1.i686
    python27-test-2.7.15-1.124.amzn1.i686
    python27-2.7.15-1.124.amzn1.i686
    python27-devel-2.7.15-1.124.amzn1.i686
    python27-tools-2.7.15-1.124.amzn1.i686

src:
    python27-2.7.15-1.124.amzn1.src

x86_64:
    python27-debuginfo-2.7.15-1.124.amzn1.x86_64
    python27-libs-2.7.15-1.124.amzn1.x86_64
    python27-devel-2.7.15-1.124.amzn1.x86_64
    python27-tools-2.7.15-1.124.amzn1.x86_64
    python27-test-2.7.15-1.124.amzn1.x86_64
    python27-2.7.15-1.124.amzn1.x86_64