Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-develUpgrade pythonUpgrade tkinterUpgrade python-tools | Dec 1, 2016 | Apr 16, 2007 |
| Oracle_linux | — | Upgrade python-develUpgrade tkinterUpgrade pythonUpgrade python-tools | Oct 16, 2024 | Apr 16, 2007 |
| Suse | — | Upgrade python-demoUpgrade libpython2_7-1_0Upgrade python-idleUpgrade python-develUpgrade python-x86Upgrade python-xmlUpgrade python-gdbmUpgrade python-baseUpgrade python-tkUpgrade python-32bitUpgrade pythonUpgrade python-curses | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python2.5Upgrade python2.4 | Nov 8, 2024 | Apr 16, 2007 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESX 3.5 to build number 226117 | Sep 2, 2010 | Apr 16, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub