Errata overview
Errata ID 258
Date 2018-10-04
Source package python2.7
Fixed in version 2.7.13-2+deb9u3
Description
This update addresses the following issues:
* DOS via regular expression catastrophic backtracking in apop() method in
  pop3lib (CVE-2018-1060)
* DOS via regular expression backtracking in difflib.IS_LINE_JUNK method in
  difflib (CVE-2018-1061)
* Missing salt initialization in _elementtree.c module (CVE-2018-14647)
* Command injection in the shutil module (CVE-2018-1000802)
Additional notes
CVE ID CVE-2018-1060
CVE-2018-1061
CVE-2018-14647
CVE-2018-1000802
UCS Bug number #47890