CVE-2012-2135
published 2012-08-14CVE-2012-2135: The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows…
PriorityP429medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
4.55%
90.6th percentile
The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| python | python | >= 2.7.0 < 2.7.4 | 2.7.4 |
| python | python | >= 3.2.0 < 3.2.4 | 3.2.4 |
| python | python | >= 3.3.0 < 3.3.3 | 3.3.3 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python 3.1 vulnerabilities
vendor_ubuntu·2012-10-24·CVSS 6.9
CVE-2008-5983 [MEDIUM] Python 3.1 vulnerabilities
Title: Python 3.1 vulnerabilities
Summary: Several security issues were fixed in Python 3.1.
It was discovered that Python would prepend an empty string to sys.path
under certain circumstances. A local attacker with write access to the
current working directory could exploit this to execute arbitrary code.
This issue only affected Ubuntu 10.04 LTS. (CVE-2008-5983)
It was discovered that the audioop module did not correctly perform input
validation. If a user or automatated system were tricked into opening a
crafted audio file, an attacker could cause a denial of service via
application crash. These issues only affected Ubuntu 10.04 LTS.
(CVE-2010-1634, CVE-2010-2089)
It was discovered that Python distutils contained a race condition when
creating the ~/.pypirc file. A local attacker co
Ubuntu
Python 3.2 vulnerabilities
vendor_ubuntu·2012-10-23·CVSS 1.9
CVE-2011-4944 [LOW] Python 3.2 vulnerabilities
Title: Python 3.2 vulnerabilities
Summary: Several security issues were fixed in Python 3.2.
It was discovered that Python distutils contained a race condition when
creating the ~/.pypirc file. A local attacker could exploit this to obtain
sensitive information. (CVE-2011-4944)
It was discovered that SimpleXMLRPCServer did not properly validate its
input when handling HTTP POST requests. A remote attacker could exploit
this to cause a denial of service via excessive CPU utilization. This issue
only affected Ubuntu 11.04 and 11.10. (CVE-2012-0845)
It was discovered that Python was susceptible to hash algorithm attacks.
An attacker could cause a denial of service under certian circumstances.
This update adds the '-R' command line option and honors setting the
PYTHONHASHSEED environment v
GHSA
GHSA-rgg2-785f-2868: The utf-16 decoder in Python 3
ghsa_unreviewed·2022-05-17
CVE-2012-2135 [MEDIUM] GHSA-rgg2-785f-2868: The utf-16 decoder in Python 3
The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2135 python3: Data leaks, memory damage and possible crash in utf-16 decoder [fedora-all]
bugzilla·2012-04-25·CVSS 6.4
CVE-2012-2135 [MEDIUM] CVE-2012-2135 python3: Data leaks, memory damage and possible crash in utf-16 decoder [fedora-all]
CVE-2012-2135 python3: Data leaks, memory damage and possible crash in utf-16 decoder [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/upda
Bugzilla
CVE-2012-2135 python3: Data leaks, memory damage and possible crash in utf-16 decoder
bugzilla·2012-04-25·CVSS 6.4
CVE-2012-2135 [MEDIUM] CVE-2012-2135 python3: Data leaks, memory damage and possible crash in utf-16 decoder
CVE-2012-2135 python3: Data leaks, memory damage and possible crash in utf-16 decoder
A security flaw was found in the way the UTF-16 decoder of Python, an interpreted, interactive, object-oriented programming language, handled error messages after processing of certain UTF-16 strings. If a Python UTF-16 module based application provided remote means to accept unsanitized input, a remote attacker could use this flaw to cause denial of service (python executable to leak data, cause memory damage and possibly crash).
Upstream ticket:
[1] http://bugs.python.org/issue14579
CVE assignment:
[2] http://www.openwall.com/lists/oss-security/2012/04/25/3
Preliminary patches against the v3.2 version:
[3] http://bugs.python.org/file25294/utf16_error_handling-3.2.patch
[4] http://bugs.python.org/fil
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670389http://bugs.python.org/issue14579http://secunia.com/advisories/51087http://secunia.com/advisories/51089http://www.openwall.com/lists/oss-security/2012/04/25/2http://www.openwall.com/lists/oss-security/2012/04/25/4http://www.ubuntu.com/usn/USN-1615-1http://www.ubuntu.com/usn/USN-1616-1http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670389http://bugs.python.org/issue14579http://secunia.com/advisories/51087http://secunia.com/advisories/51089http://www.openwall.com/lists/oss-security/2012/04/25/2http://www.openwall.com/lists/oss-security/2012/04/25/4http://www.ubuntu.com/usn/USN-1615-1http://www.ubuntu.com/usn/USN-1616-1
2012-08-14
Published