Heap overflow in zipimporter
module.
Dates:
Disclosure date: 2016-01-21 (Python issue bpo-26171 reported)
Python 2.7.12 (2016-06-25) fixed by commit 64ea192 (branch 2.7) (2016-01-21)
Python 3.3.7 (2017-09-19) fixed by commit d751040 (branch 3.3) (2016-09-14)
Python 3.4.5 (2016-06-25) fixed by commit c4032da (branch 3.4) (2016-01-21)
Python 3.5.2 (2016-06-25) fixed by commit c4032da (branch 3.4) (2016-01-21)
Python 3.6.0 (2016-12-22) fixed by commit d751040 (branch 3.3) (2016-09-14)
heap overflow in zipimporter module.
Python issue: bpo-26171
Creation date: 2016-01-21
Reporter: Insu Yun
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
CVE ID: CVE-2016-5636
Published: 2016-09-02
CVSS Score: 10.0
Timeline using the disclosure date 2016-01-21 as reference:
2016-01-21: Python issue bpo-26171 reported by Insu Yun
2016-01-21: commit 64ea192 (branch 2.7)
2016-01-21: commit c4032da (branch 3.4)
2016-06-25 (+156 days): Python 2.7.12 released
2016-06-25 (+156 days): Python 3.4.5 released
2016-06-25 (+156 days): Python 3.5.2 released
2016-09-02 (+225 days): CVE-2016-5636 published
2016-09-14 (+237 days): commit d751040 (branch 3.3)
2016-12-22: Python 3.6.0 released
2017-09-19 (+607 days): Python 3.3.7 released
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4