Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-develUpgrade pythonUpgrade tkinterUpgrade python-tools | Dec 1, 2016 | Apr 16, 2007 |
| Oracle_linux | — | Upgrade python-toolsUpgrade pythonUpgrade tkinterUpgrade python-devel | Oct 16, 2024 | Apr 16, 2007 |
| Suse | — | Upgrade python-32bitUpgrade pythonUpgrade python-baseUpgrade python-tkUpgrade python-cursesUpgrade python-xmlUpgrade python-idleUpgrade python-develUpgrade python-demoUpgrade libpython2_7-1_0Upgrade python-x86Upgrade python-gdbm | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python2.5Upgrade python2.4 | Nov 8, 2024 | Apr 16, 2007 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 3.5 to build number 226117Upgrade VMware ESX 4.0 to build number 208167 | Sep 2, 2010 | Apr 16, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub