CVE-2018-17793

Publication date 30 September 2018

Last updated 4 August 2025


Ubuntu priority

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

Read the notes from the security team

Status

Package Ubuntu Release Status
python-virtualenv 19.04 disco Ignored
18.10 cosmic Ignored end of life
18.04 LTS bionic Ignored
16.04 LTS xenial Ignored
14.04 LTS trusty Ignored

Notes


msalvatore

Upstream has asked MITRE to reject this as not a security vulnerability. Upstream says, "Python in the virtualenv "sandbox" is 0% secure; it's neither designed to nor does it provide any protection against malicious code. You seem very confused about the purpose of virtualenv." https://github.com/pypa/virtualenv/issues/1207#issuecomment-426616819