CVE-2012-2135

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler … (CVE-2012-2135)

Description

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.

Metrics

Severity
none
no public PoC known
91.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
4.5 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2012-08-14 22:00 UTC

Affected operating systems

  • linux

    debian / debian_linux6.0

  • linux

    canonical / ubuntu_linux10.04

  • linux

    canonical / ubuntu_linux11.04

  • linux

    canonical / ubuntu_linux11.10

  • linux

    canonical / ubuntu_linux12.04

  • linux

    canonical / ubuntu_linux12.10

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • python

    python2.7.0 – 2.7.4

  • python

    python3.2.0 – 3.2.4

  • python

    python3.3.0 – 3.3.3

References & sources

IDCVE-2012-2135