CVE Vulnerabilities

CVE-2007-2052

Off-by-one Error

Published: Apr 16, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
PythonPython2.4.0 (including)2.4.0 (including)
PythonPython2.5.0 (including)2.5.0 (including)
Red Hat Enterprise Linux 2.1RedHatpython-0:1.5.2-43.72.2*
Red Hat Enterprise Linux 3RedHatpython-0:2.2.3-6.8*
Red Hat Enterprise Linux 4RedHatpython-0:2.3.4-14.4.el4_6.1*
Red Hat Enterprise Linux 5RedHatpython-0:2.4.3-24.el5_3.6*
Red Hat Network Satellite Server v 4.2RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 4.2 (RHEL3)RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.0RedHatrhn-solaris-bootstrap-0:5.0.2-3*
Red Hat Network Satellite Server v 5.0RedHatrhn_solaris_bootstrap_5_0_2_3-0:1-0*
Red Hat Network Satellite Server v 5.1RedHatrhn-solaris-bootstrap-0:5.1.1-3*
Red Hat Network Satellite Server v 5.1RedHatrhn_solaris_bootstrap_5_1_1_3-0:1-0*
Python2.4Ubuntudapper*
Python2.4Ubuntuedgy*
Python2.4Ubuntuupstream*
Python2.5Ubuntuedgy*
Python2.5Ubuntuupstream*

Potential Mitigations

References