bugs.python.orgConfirmation
http://bugs.python.org/issue20246 CVE-2014-1912
Python - 'socket.recvfrom_into()' Remote Buffer Overflow
Record summary
CVE-2014-1912 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPython - 'socket.recvfrom_into()' Remote Buffer OverflowExploitDB exploitby Sha0Not analyzed1 file
References
Showing 12 of 20hg.python.orgConfirmation
http://hg.python.org/cpython/rev/87673659d8f7 APPLE-SA-2015-08-13-2Vendor advisory
http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.html openSUSE-SU-2014:0518Vendor advisory
http://lists.opensuse.org/opensuse-updates/2014-04/msg00035.html openSUSE-SU-2014:0597Vendor advisory
http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html pastebin.com
http://pastebin.com/raw.php?i=GHXSmNEg RHSA-2015:1064Vendor advisory
http://rhn.redhat.com/errata/RHSA-2015-1064.html RHSA-2015:1330Vendor advisory
http://rhn.redhat.com/errata/RHSA-2015-1330.html DSA-2880Vendor advisory
http://www.debian.org/security/2014/dsa-2880 31875exploit
http://www.exploit-db.com/exploits/31875 [oss-security] 20140212 Re: CVE request? buffer overflow in socket.recvfrom_intomailing list
http://www.openwall.com/lists/oss-security/2014/02/12/16 oracle.comConfirmation
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html