CVE-2021-3177
PoC —CVSS 3.1
9.8 critical
EPSS
23%p98
Published
()
Modified
Description
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
- Vendors
- pythonfedoraprojectnetappdebianoracle
- Products
- python, fedora, active iq unified manager, ontap select deploy administration utility, debian linux, communications cloud native core network function cloud native environment, communications offline mediation controller, communications pricing design center, enterprise manager ops center, zfs storage appliance kit
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.