PT-2018-3713 · Python+2 · Python+2
Published
2018-04-13
·
Updated
2024-07-11
·
CVE-2019-17514
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Python versions prior to 2016
Description
The issue is related to incorrect calculations in the library/glob.html package of Python. It may allow a remote attacker to impact the integrity of protected information. The documentation of library/glob.html before 2016 contained potentially misleading information about sorting, which could affect security-relevant code in other domains.
Recommendations
For Python versions prior to 2016, consider updating to a newer version that includes accurate documentation for library/glob.html. As a temporary workaround, call the sort() function directly, as implemented in newer versions of Willoughby nmr-data compilation-p2.py and nmr-data compilation-p3.py.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Python
Ubuntu