The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 6.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Suse | — | Upgrade python3-develUpgrade python3-debuginfo-32bitUpgrade python3-devel-debuginfoUpgrade libpython3_2mu1_0-x86Upgrade python3-xml-debuginfoUpgrade python3-baseUpgrade python3-tkUpgrade libpython3_2mu1_0-32bitUpgrade python3-base-debuginfoUpgrade python3-toolsUpgrade libpython3_2mu1_0-debuginfo-x86-debuginfoUpgrade python3-debugsourceUpgrade python3-dbmUpgrade python3-xmlUpgrade python3-tk-debuginfoUpgrade libpython3_2mu1_0-debuginfoUpgrade libpython3_2mu1_0Upgrade python3-debuginfoUpgrade python3-debuginfo-x86Upgrade python3-idleUpgrade python3-32bitUpgrade python3-doc-pdfUpgrade python3-curses-debuginfoUpgrade python3-dbm-debuginfoUpgrade python3-docUpgrade python3-debuginfo-x86-debuginfoUpgrade python3Upgrade python3-cursesUpgrade python3-base-debugsourceUpgrade libpython3_2mu1_0-debuginfo-x86Upgrade python3-x86Upgrade python3-2to3Upgrade libpython3_2mu1_0-debuginfo-32bit | Dec 12, 2013 | Aug 14, 2012 |
| Ubuntu | — | Upgrade python3.2-minimalUpgrade python3.2Upgrade python3.1-minimalUpgrade python3.1 | Nov 8, 2024 | Aug 14, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub