ZeroHour

CVE-2021-3177

PoC
CVSS 3.1
9.8 critical
EPSS
23%p98
Published
()
Modified
Description

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

Vendors
pythonfedoraprojectnetappdebianoracle
Products
python, fedora, active iq unified manager, ontap select deploy administration utility, debian linux, communications cloud native core network function cloud native environment, communications offline mediation controller, communications pricing design center, enterprise manager ops center, zfs storage appliance kit
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.