The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade pythonUpgrade python+ipv6 | Dec 10, 2025 | Feb 3, 2005 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | May 2, 2005 |
| Suse | — | Upgrade python-x86Upgrade python-64bitUpgrade python-32bitUpgrade python | Feb 17, 2015 | May 2, 2005 |
| Ubuntu | — | Upgrade python2.3 | Nov 8, 2024 | May 2, 2005 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub