Опубликовано: 09 авг. 2021
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5
Описание
Integer overflow in pywin32
An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-32559
- https://github.com/mhammond/pywin32/issues/1700
- https://github.com/mhammond/pywin32/pull/1701
- https://github.com/advisories/GHSA-hwfp-hg2m-9vr2
- https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0017/FEYE-2021-0017.md
- https://github.com/mhammond/pywin32/releases
- https://github.com/pypa/advisory-database/tree/main/vulns/pywin32/PYSEC-2021-112.yaml
Пакеты
Наименование
pywin32
pip
Затронутые версииВерсия исправления
< 301
301
Связанные уязвимости
CVSS3: 6.5
nvd
больше 4 лет назад
An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.
CVSS3: 6.5
fstec
почти 2 года назад
Уязвимость пакета pywin32 платформы для операционного анализа Splunk Enterprise, позволяющая нарушителю вызвать отказ в обслуживании