Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-1912

Опубликовано: 14 янв. 2014
Источник: redhat
CVSS2: 5.1
EPSS Средний

Описание

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

It was discovered that the socket.recvfrom_into() function failed to check the size of the supplied buffer. This could lead to a buffer overflow when the function was called with an insufficiently sized buffer.

Отчет

This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 5 as they did not include the vulnerable socket.recvfrom_into() function. This issue was also corrected in the version of python shipped with Red Hat Enterprise Linux 7.0 prior to release. The Red Hat Security Response Team has rated this issue as having Moderate security impact. A future update may address this issue in Red Hat Software Collections. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonNot affected
Red Hat Enterprise Linux 7pythonNot affected
Red Hat Software Collectionspython27-pythonAffected
Red Hat Software Collectionspython33-pythonWill not fix
Red Hat Software Collectionsrh-python34-pythonNot affected
Red Hat Enterprise Linux 6pythonFixedRHSA-2015:133020.07.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6python27FixedRHSA-2015:106404.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6python27-pythonFixedRHSA-2015:106404.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6python27-python-pipFixedRHSA-2015:106404.06.2015
Red Hat Software Collections for Red Hat Enterprise Linux 6python27-python-setuptoolsFixedRHSA-2015:106404.06.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=1062370python: buffer overflow in socket.recvfrom_into()

EPSS

Процентиль: 97%
0.31435
Средний

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

nvd
больше 11 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

debian
больше 11 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socket ...

github
больше 3 лет назад

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

oracle-oval
больше 10 лет назад

ELSA-2015-1330: python security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 97%
0.31435
Средний

5.1 Medium

CVSS2

Уязвимость CVE-2014-1912