CVE Vulnerabilities

CVE-2012-2135

Published: Aug 14, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The utf-16 decoder in Python 3.1 through 3.3 does not update the aligned_end variable after calling the unicode_decode_call_errorhandler function, which allows remote attackers to obtain sensitive information (process memory) or cause a denial of service (memory corruption and crash) via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
PythonPython2.7.0 (including)2.7.4 (excluding)
PythonPython3.2.0 (including)3.2.4 (excluding)
PythonPython3.3.0 (including)3.3.3 (excluding)
Python3.1Ubuntulucid*
Python3.1Ubuntunatty*
Python3.2Ubuntunatty*
Python3.2Ubuntuoneiric*
Python3.2Ubuntuprecise*
Python3.2Ubuntuupstream*

References