CVE-2005-0089
The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instan… (CVE-2005-0089)
noneEPSS 6%
Description
The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.
Metrics
Severity
none
55.73
no public PoC known
92.9 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2005-02-06 05:00 UTC
—
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
python
python2.3.5
python
python
References & sources
- http://securitytracker.com/id?1013083vdb-entryx_refsource_SECTRACK
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19217vdb-entryx_refsource_XF
- http://www.python.org/security/PSF-2005-001/x_refsource_CONFIRM
- http://marc.info/?l=bugtraq&m=110746469728728&w=2mailing-listx_refsource_BUGTRAQ
- http://www.trustix.org/errata/2005/0003/vendor-advisoryx_refsource_TRUSTIX
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9811vdb-entrysignaturex_refsource_OVAL
- http://www.securityfocus.com/bid/12437vdb-entryx_refsource_BID
- http://secunia.com/advisories/14128third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2005/dsa-666vendor-advisoryx_refsource_DEBIAN
- http://python.org/security/PSF-2005-001/patch-2.2.txtx_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:035vendor-advisoryx_refsource_MANDRAKE
- http://www.redhat.com/support/errata/RHSA-2005-108.htmlvendor-advisoryx_refsource_REDHAT
IDCVE-2005-0089