← back
CVE-2018-1060mediumCWE-20

CVE-2018-1060

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.3epss 5.3%
exploitation probability
5.3%top 8% of all CVEs
observed exploitation
nono source reports it
python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Affected products
[UNKNOWN] · python