DescriptionIn Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python2.7 (PTS)jessie, jessie (lts)2.7.9-2-ds1-1+deb8u11fixed
stretch (security)2.7.13-2+deb9u6fixed
stretch (lts), stretch2.7.13-2+deb9u8fixed
buster (security)2.7.16-2+deb10u3fixed
python3.4 (PTS)jessie, jessie (lts)3.4.2-1+deb8u15fixed
python3.5 (PTS)stretch (security)3.5.3-1+deb9u5fixed
stretch (lts), stretch3.5.3-1+deb9u8fixed
python3.7 (PTS)buster3.7.3-2+deb10u3fixed
buster (security)3.7.3-2+deb10u6fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python2.7source(unstable)(not affected)
python3.4source(unstable)(not affected)
python3.5source(unstable)(not affected)
python3.7source(unstable)(not affected)
python3.8source(unstable)(not affected)


- python3.8 <not-affected> (Windows-specific)
- python3.7 <not-affected> (Windows-specific)
- python2.7 <not-affected> (Vulnerable code not present)
- python3.4 <not-affected> (Windows-specific)
- python3.5 <not-affected> (Windows-specific)

Search for package or bug name: Reporting problems