CVE Database
/

CVE-2018-20406

Back to search

CVE-2018-20406

Published: Dec 23, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the pickle format is used for serializing tens or hundreds of gigabytes of data. This issue is fixed in: v3.4.10, v3.4.10rc1; v3.5.10, v3.5.10rc1, v3.5.7, v3.5.7rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.7, v3.6.7rc1, v3.6.7rc2, v3.6.8, v3.6.8rc1, v3.6.9, v3.6.9rc1; v3.7.1, v3.7.1rc1, v3.7.1rc2, v3.7.2, v3.7.2rc1, v3.7.3, v3.7.3rc1, v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2019-6e1938a3c5
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-6baeb15da3
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-cf725dd20b
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-6b02154aa0
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-7d9f3cf3ce
vendor-advisory
x_refsource_FEDORA
FEDORA-2019-51f1e08207
vendor-advisory
x_refsource_FEDORA
USN-4127-2
vendor-advisory
x_refsource_UBUNTU
USN-4127-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:3725
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2020:0086
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now