Lucene search

K
osvGoogleOSV:DSA-458-3
HistoryOct 10, 2004 - 12:00 a.m.

python2.2 - buffer overflow

2004-10-1000:00:00
Google
osv.dev
8

EPSS

0.068

Percentile

93.9%

This security advisory corrects DSA 458-2 which caused a problem in
the gethostbyaddr routine.

The original advisory said:

>
> Sebastian Schmidt discovered a buffer overflow bug in Python’s
> getaddrinfo function, which could allow an IPv6 address, supplied by a
> remote attacker via DNS, to overwrite memory on the stack.
>
>
> This bug only exists in python 2.2 and 2.2.1, and only when IPv6
> support is disabled. The python2.2 package in Debian woody meets
> these conditions (the ‘python’ package does not).
>
>
>

For the stable distribution (woody), this bug has been fixed in
version 2.2.1-4.6.

The testing and unstable distribution (sarge and sid) are not
affected by this problem.

We recommend that you update your python2.2 packages.

EPSS

0.068

Percentile

93.9%