CVE-2014-1912: Buffer Overflow
Published Feb 28, 2014
·Updated
Buffer overflow in the socket.recvfrominto function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
Affected Software
52 affected components
Python Python=2.5.1
Python Python=2.5.2
Python Python=2.5.3
Python Python=2.5.4
Python Python=2.5.6
Python Python=2.5.150
Python Python=2.6.1
Python Python=2.6.2
Python Python=2.6.3
Python Python=2.6.4
Python Python=2.6.5
Python Python=2.6.6
Python Python=2.6.7
Python Python=2.6.8
Python Python=2.6.2150
Python Python=2.6.6150
Python Python=2.7.1
Python Python=2.7.1-rc1
Python Python=2.7.2-rc1
Python Python=2.7.3
Python Python=2.7.4
Python Python=2.7.5
Python Python=2.7.6
Python Python=2.7.1150
Python Python=2.7.1150
Python Python=2.7.2150
Apple iOS and macOS<=10.10.4
Python Python=3.0
Python Python=3.0.1
Python Python=3.1
Python Python=3.1.1
Python Python=3.1.2
Python Python=3.1.3
Python Python=3.1.4
Python Python=3.1.5
Python Python=3.1.2150
Python Python=3.2
Python Python=3.2-alpha
Python Python=3.2.0
Python Python=3.2.1
Python Python=3.2.2
Python Python=3.2.3
Python Python=3.2.4
Python Python=3.2.5
Python Python=3.2.2150
Python Python=3.3
Python Python=3.3-beta2
Python Python=3.3.0
Python Python=3.3.1
Python Python=3.3.2
Python Python=3.3.3
Python Python=3.4-alpha1
Remediation
Patch Available
Event History
Feb 28, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Mar 1, 2014
Data Sourced
via NVD·12:55 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-1912?
CVE-2014-1912 has been assigned a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2014-1912?
To fix CVE-2014-1912, upgrade Python to a version that is patched, such as 2.7.7 or later, or 3.3.4 or later.
3
What types of systems are affected by CVE-2014-1912?
CVE-2014-1912 affects multiple versions of Python 2.5 through 2.7, as well as Python 3.x up to 3.4rc1.
4
Who can exploit CVE-2014-1912?
Remote attackers can exploit CVE-2014-1912 by sending crafted input to applications using vulnerable versions of Python.
5
Are there known exploits for CVE-2014-1912?
Yes, there are known exploits for CVE-2014-1912 that have been demonstrated in the wild.