FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-1912

This CVE name corresponds to:

Entered Topic
2014-03-01 Python -- buffer overflow in socket.recvfrom_into()

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-1912
Phase Assigned(20140207)

Description

Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

References

Source Reference
EXPLOIT-DB 31875
MLIST [oss-security] 20140212 Re: CVE request? buffer overflow in socket.recvfrom_into
MISC http://pastebin.com/raw.php?i=GHXSmNEg
MISC https://www.trustedsec.com/february-2014/python-remote-code-execution-socket-recvfrom_into/
CONFIRM http://bugs.python.org/issue20246
CONFIRM http://hg.python.org/cpython/rev/87673659d8f7
CONFIRM https://support.apple.com/kb/HT205031
APPLE APPLE-SA-2015-08-13-2
DEBIAN DSA-2880
SUSE openSUSE-SU-2014:0597
UBUNTU USN-2125-1
SECTRACK 1029831