7.5

CVE-2014-1912

Exploit
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Python ≫ Python Version 2.5.1
Python ≫ Python Version 2.5.2
Python ≫ Python Version 2.5.3
Python ≫ Python Version 2.5.4
Python ≫ Python Version 2.5.6
Python ≫ Python Version 2.5.150
Python ≫ Python Version 2.6.1
Python ≫ Python Version 2.6.2
Python ≫ Python Version 2.6.3
Python ≫ Python Version 2.6.4
Python ≫ Python Version 2.6.5
Python ≫ Python Version 2.6.6
Python ≫ Python Version 2.6.7
Python ≫ Python Version 2.6.8
Python ≫ Python Version 2.6.2150
Python ≫ Python Version 2.6.6150
Python ≫ Python Version 2.7.1
Python ≫ Python Version 2.7.1 Update rc1
Python ≫ Python Version 2.7.2 Update rc1
Python ≫ Python Version 2.7.3
Python ≫ Python Version 2.7.4
Python ≫ Python Version 2.7.5
Python ≫ Python Version 2.7.6
Python ≫ Python Version 2.7.1150
Python ≫ Python Version 2.7.1150 HwPlatform x64
Python ≫ Python Version 2.7.2150
Apple ≫ macOS X Version <= 10.10.4
Python ≫ Python Version 3.0
Python ≫ Python Version 3.0.1
Python ≫ Python Version 3.1
Python ≫ Python Version 3.1.1
Python ≫ Python Version 3.1.2
Python ≫ Python Version 3.1.3
Python ≫ Python Version 3.1.4
Python ≫ Python Version 3.1.5
Python ≫ Python Version 3.1.2150 HwPlatform x64
Python ≫ Python Version 3.2
Python ≫ Python Version 3.2 Update alpha
Python ≫ Python Version 3.2.0
Python ≫ Python Version 3.2.1
Python ≫ Python Version 3.2.2
Python ≫ Python Version 3.2.3
Python ≫ Python Version 3.2.4
Python ≫ Python Version 3.2.5
Python ≫ Python Version 3.2.2150
Python ≫ Python Version 3.3
Python ≫ Python Version 3.3 Update beta2
Python ≫ Python Version 3.3.0
Python ≫ Python Version 3.3.1
Python ≫ Python Version 3.3.2
Python ≫ Python Version 3.3.3
Python ≫ Python Version 3.4 Update alpha1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 28.32% 0.979
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html
https://support.apple.com/kb/HT205031
Vendor Advisory
http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.html
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
http://www.debian.org/security/2014/dsa-2880
http://bugs.python.org/issue20246
Patch
http://hg.python.org/cpython/rev/87673659d8f7
http://lists.opensuse.org/opensuse-updates/2014-04/msg00035.html
http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html
http://pastebin.com/raw.php?i=GHXSmNEg
Exploit
http://rhn.redhat.com/errata/RHSA-2015-1064.html
http://rhn.redhat.com/errata/RHSA-2015-1330.html
http://www.exploit-db.com/exploits/31875
Exploit
http://www.openwall.com/lists/oss-security/2014/02/12/16
http://www.securityfocus.com/bid/65379
http://www.securitytracker.com/id/1029831
http://www.ubuntu.com/usn/USN-2125-1
https://security.gentoo.org/glsa/201503-10
https://www.trustedsec.com/february-2014/python-remote-code-execution-socket-recvfrom_into/
Exploit