V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2007-2052
DEB
MediumConfirmedExploit available

Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be u…

CVSS
5.0
Medium
EPSS
0.12
p95
Published
2007-01-01
Updated
2007-01-01
Description

Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.

Tags · CWE
CWE-193
Affected products
Python
CVSS vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Timeline
2007-01-01
Published
2007-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.125 · p95
Known exploited (KEV)
No
Known exploits — Сканер-ВС
30018
exploitdb · https://www.exploit-db.com/exploits/30018
Enterprise
Affected products
ProductVendorStatus
pythonTracked
pythonTracked
pythonTracked
pythonTracked
python2.3Tracked
python2.4Tracked
python2.5Tracked
rhn-solaris-bootstrapTracked
rhn-solaris-bootstrapTracked
rhn-solaris-bootstrapTracked
rhn-solaris-bootstrapTracked
rhn_solaris_bootstrap_5_0_2_3Tracked
rhn_solaris_bootstrap_5_0_2_3Tracked
rhn_solaris_bootstrap_5_0_2_3Tracked
rhn_solaris_bootstrap_5_1_1_3Tracked
python*Tracked
Source databases
DEB
CVE
RED