Описание
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
python3.9 | not-affected | package | ||
python3.7 | fixed | 3.7.7-1 | package | |
python2.7 | removed | package | ||
python2.7 | fixed | 2.7.18-8+deb11u1 | bullseye | package |
Примечания
https://bugs.python.org/issue39421
https://github.com/python/cpython/issues/83602
https://github.com/python/cpython/commit/79f89e6e5a659846d1068e8b1bd8e491ccdef861 (v3.9.0a3)
https://github.com/python/cpython/commit/993811ffe75c2573f97fb3fd1414b34609b8c8db (v3.8.2rc1)
https://github.com/python/cpython/commit/958064f8d2b84062b0582bbae911df8ccfc11fd6 (v3.7.7rc1)
https://github.com/python/cpython/commit/c563f409ea30bcb0623d785428c9257917371b76 (v3.6.11rc1)
EPSS
Связанные уязвимости
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
Уязвимость интерпретатора языка программирования Python, связанная с использованием памяти после её освобождения, позволяющая нарушителю вызвать отказ в обслуживании
EPSS