Vulnerability record · CVE-2018-1000807 · published 8 October 2018
CVE-2018-1000807: Pyopenssl use after free vulnerability
Pyopenssl · Pyopenssl
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.
Description
Python Cryptographic Authority pyopenssl version prior to version 17.5.0 contains a CWE-416: Use After Free vulnerability in X509 object handling that can result in Use after free can lead to possible denial of service or remote code execution.. This attack appear to be exploitable via Depends on the calling application and if it retains a reference to the memory.. This vulnerability appears to have been fixed in 17.5.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00014.html | Mailing ListThird Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0085 | Third Party Advisory |
| https://github.com/pyca/pyopenssl/commit/e73818600065821d588af475b024f4eb518c3509 | |
| https://github.com/pyca/pyopenssl/pull/723 | PatchThird Party Advisory |
| https://usn.ubuntu.com/3813-1/ | Third Party Advisory |
| http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00014.html | Mailing ListThird Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:0085 | Third Party Advisory |
| https://github.com/pyca/pyopenssl/commit/e73818600065821d588af475b024f4eb518c3509 | |
| https://github.com/pyca/pyopenssl/pull/723 | PatchThird Party Advisory |
| https://usn.ubuntu.com/3813-1/ | Third Party Advisory |
Track CVE-2018-1000807 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-1000807), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.