CVE-2018-1060: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 5% chance of exploitation in the next 30 days.

python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 16.04 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only
  • Python Python: from 2.7.0, before 2.7.15 (fixed in 2.7.15); from 3.0.0, before 3.4.9 (fixed in 3.4.9); from 3.5.0, before 3.5.6 (fixed in 3.5.6); after 3.6.0, before 3.6.5 (fixed in 3.6.5)
  • Red Hat Ansible Tower: version 3.3 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only

Published 2018-06-18. Last modified 2026-10-08.