Python Missing Initialization of Resource Vulnerability - CVE-2018-14647 - Vulnerability Database

Python Missing Initialization of Resource Vulnerability - CVE-2018-14647

High
Reference: CVE-2018-14647
Title: Python Missing Initialization of Resource Vulnerability
Overview:

Python39s elementtree C accelerator failed to initialise Expat39s hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat39s internal data structures consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0 3.6.0 through 3.6.6 3.5.0 through 3.5.6 3.4.0 through 3.4.9 2.7.0 through 2.7.15.