Back to search
CVE-2012-2135
Published: Aug 14, 2012
Modified: Aug 6, 2024
PUBLISHED
Description
The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-1615-1
vendor-advisory
x_refsource_UBUNTU
51087
third-party-advisory
x_refsource_SECUNIA
USN-1616-1
vendor-advisory
x_refsource_UBUNTU
http://bugs.python.org/issue14579
x_refsource_MISC
51089
third-party-advisory
x_refsource_SECUNIA
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670389
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now