python: unsafe dll loading in getpathp.c on Windows
Published Jan 28, 2020
5.5
MEDIUMCVSS 3.1
EPSS 1.48%
Description
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.
Affected products
No data.
No data.
Red Hat Enterprise Linux 5
python
Not affected
Red Hat Enterprise Linux 6
python
Not affected
Red Hat Enterprise Linux 7
python
Not affected
Red Hat Enterprise Linux 7
python3
Not affected
Red Hat Enterprise Linux 8
python27:2.7/python2
Not affected
Red Hat Enterprise Linux 8
python3
Not affected
Red Hat Enterprise Linux 8
python36:3.6/python36
Not affected
Red Hat Enterprise Linux 8
python38:3.8/python38
Not affected
Red Hat Quay 3
python27
Not affected
Red Hat Software Collections
python27-python
Not affected
Red Hat Software Collections
rh-python36-python
Not affected
Red Hat Software Collections
rh-python38-python
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | python | Not affected | n/a |
| Red Hat Enterprise Linux 6 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python | Not affected | n/a |
| Red Hat Enterprise Linux 7 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python27:2.7/python2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python3 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python36:3.6/python36 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | python38:3.8/python38 | Not affected | n/a |
| Red Hat Quay 3 | python27 | Not affected | n/a |
| Red Hat Software Collections | python27-python | Not affected | n/a |
| Red Hat Software Collections | rh-python36-python | Not affected | n/a |
| Red Hat Software Collections | rh-python38-python | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This does not affect python as shipped with Red Hat Enterprise Linux of any version, Red Hat Software Collections, or any other Red Hat product. The behavior is specific to Windows proprietary APIs and the Portable Executable (DLL) loading processes.
References (6)
- https://access.redhat.com/security/cve/CVE-2020-8315 Vendor Advisory
- https://bugs.python.org/issue39401 x_refsource_MISCIssue TrackingPatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1855039 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29182 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8315
- https://www.cve.org/CVERecord?id=CVE-2020-8315
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-8315 | Vendor Advisory | |
| https://bugs.python.org/issue39401 | x_refsource_MISCIssue TrackingPatchVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1855039 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29182 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-8315 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-8315 |
Change history (0)
No recorded changes yet.