Google: dev-lang/python: security update to 17162.279.24

critical Tenable Self-Hosted Container Security Plugin ID 452265

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of
Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive
function) that can result in Denial of service, Information gain via injection of arbitrary files on the
system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the
function. This vulnerability appears to have been fixed in after commit
add531a1e55b0a739b0f42582f1c9747e5649ace. (CVE-2018-1000802)

Solution

Update the dev-lang/python library and its related packages to version 17162.279.24 or later.

See Also

https://storage.googleapis.com/cos-oval-vulnerability-feed/cos-101.oval.xml.tar.gz

Plugin Details

Severity: Critical

ID: 452265

Version: Revision 1.1

Type: Local

Published: 10/1/2026

Updated: 10/1/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

Vendor

Vendor Severity: HIGH

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-1000802

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 9/18/2018

Reference Information

CVE: CVE-2018-1000802