CVE-2014-7185
published 2014-10-08CVE-2014-7185: Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large…
PriorityP431medium6.4CVSS 2.0
AVNACLAuNCPINAP
EPSS
5.31%
91.8th percentile
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.10.4 | — |
| apple | os_x_yosemite_v10.10.5_and_security_update_2015-006 | — | — |
| debian | python2.7 | < python2.7 2.7.8-1 (bullseye) | python2.7 2.7.8-1 (bullseye) |
| python | python | <= 2.7.7 | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
| python | python | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.4LOW
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2015-06-25·CVSS 7.5
CVE-2013-1752 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that multiple Python protocol libraries incorrectly
limited certain data when connecting to servers. A malicious ftp, http,
imap, nntp, pop or smtp server could use this issue to cause a denial of
service. (CVE-2013-1752)
It was discovered that the Python xmlrpc library did not limit unpacking
gzip-compressed HTTP bodies. A malicious server could use this issue to
cause a denial of service. (CVE-2013-1753)
It was discovered that the Python json module incorrectly handled a certain
argument. An attacker could possibly use this issue to read arbitrary
memory and expose sensitive information. This issue only affected Ubuntu
12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-4616)
It was discover
Red Hat
python: buffer() integer overflow leading to out of bounds read
vendor_redhat·2014-06-23·CVSS 6.4
CVE-2014-7185 [MEDIUM] CWE-190 python: buffer() integer overflow leading to out of bounds read
python: buffer() integer overflow leading to out of bounds read
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
An integer overflow flaw was found in the way the buffer() function handled its offset and size arguments. An attacker able to control those arguments could use this flaw to disclose portions of the application memory or cause it to crash.
Statement: This issue affects the versions of python as shipped with Red Hat Enterprise Linux 7. A future update may address this issue.
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not
Debian
CVE-2014-7185: python2.7 - Integer overflow in bufferobject.c in Python before 2.7.8 allows context-depende...
vendor_debian·2014·CVSS 6.4
CVE-2014-7185 [MEDIUM] CVE-2014-7185: python2.7 - Integer overflow in bufferobject.c in Python before 2.7.8 allows context-depende...
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
Scope: local
bullseye: resolved (fixed in 2.7.8-1)
Apple
CVE-2014-7185: OS X Yosemite v10.10.5 and Security Update 2015-006
vendor_apple·CVSS 6.4
CVE-2014-7185 [MEDIUM] CVE-2014-7185: OS X Yosemite v10.10.5 and Security Update 2015-006
Apple Security Update: About the security content of OS X Yosemite v10.10.5 and Security Update 2015-006
Product: OS X Yosemite v10.10.5 and Security Update 2015-006
CVE: CVE-2014-7185
Component: CVE-2014-7185
GHSA
GHSA-4p82-prjq-g7wr: Integer overflow in bufferobject
ghsa_unreviewed·2022-05-13
CVE-2014-7185 [MEDIUM] GHSA-4p82-prjq-g7wr: Integer overflow in bufferobject
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
OSV
python2.7, python3.2, python3.4 vulnerabilities
osv·2015-06-25·CVSS 7.5
CVE-2013-1752 [HIGH] python2.7, python3.2, python3.4 vulnerabilities
python2.7, python3.2, python3.4 vulnerabilities
It was discovered that multiple Python protocol libraries incorrectly
limited certain data when connecting to servers. A malicious ftp, http,
imap, nntp, pop or smtp server could use this issue to cause a denial of
service. (CVE-2013-1752)
It was discovered that the Python xmlrpc library did not limit unpacking
gzip-compressed HTTP bodies. A malicious server could use this issue to
cause a denial of service. (CVE-2013-1753)
It was discovered that the Python json module incorrectly handled a certain
argument. An attacker could possibly use this issue to read arbitrary
memory and expose sensitive information. This issue only affected Ubuntu
12.04 LTS and Ubuntu 14.04 LTS. (CVE-2014-4616)
It was discovered that the Python CGIHTTPServer incor
OSV
CVE-2014-7185: Integer overflow in bufferobject
osv·2014-10-08·CVSS 6.4
CVE-2014-7185 [MEDIUM] CVE-2014-7185: Integer overflow in bufferobject
Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function.
No detection rules found.
No public exploits indexed.
http://bugs.python.org/issue21831http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/139663.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1064.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1330.htmlhttp://www.openwall.com/lists/oss-security/2014/09/23/5http://www.openwall.com/lists/oss-security/2014/09/25/47http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70089https://bugzilla.redhat.com/show_bug.cgi?id=1146026https://exchange.xforce.ibmcloud.com/vulnerabilities/96193https://security.gentoo.org/glsa/201503-10https://support.apple.com/kb/HT205031http://bugs.python.org/issue21831http://lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/139663.htmlhttp://lists.opensuse.org/opensuse-updates/2014-10/msg00016.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1064.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1330.htmlhttp://www.openwall.com/lists/oss-security/2014/09/23/5http://www.openwall.com/lists/oss-security/2014/09/25/47http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70089https://bugzilla.redhat.com/show_bug.cgi?id=1146026https://exchange.xforce.ibmcloud.com/vulnerabilities/96193https://security.gentoo.org/glsa/201503-10https://support.apple.com/kb/HT205031
2014-10-08
Published