Back

MEDIUM

python off-by-one locale.strxfrm() (possible memory disclosure)

Published Apr 16, 2007

Description

Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.

Affected products

Remediation

Red Hat statement

The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: https://access.redhat.com/security/updates/classification/

Metrics

Weaknesses (1)

References (42)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 16, 2007
Updated Aug 7, 2024
Reserved Apr 16, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Apr 2, 2007