5

CVE-2007-2052

Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PythonPython Version2.4.0
PythonPython Version2.5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 13.74% 0.942
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-193 Off-by-one Error

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

http://www.securityfocus.com/bid/23887
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2007/1465
Third Party Advisory
Broken Link
http://www.vupen.com/english/advisories/2008/0637
Third Party Advisory
Broken Link
http://www.vupen.com/english/advisories/2009/3316
Third Party Advisory
Broken Link