vendor:
Python
by:
dx/vaxen and posidron
7,2
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Python
Affected Version From: Python 2.4.2
Affected Version To: Python 2.4.2
Patch Exists: YES
Related CWE: N/A
CPE: a:python:python:2.4.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2006
Python <= 2.4.2 realpath() Local Stack Overflow
Python <= 2.4.2 is vulnerable to a local stack overflow vulnerability. This exploit is against VA Space Randomization. The bug was found and developed by dx/vaxen (Gotfault Security) and posidron (Tripbit Research Group). The exploit creates a directory with a long path name and then executes a python script in that directory. The python script contains shellcode which is then executed.
Mitigation:
Upgrade to Python 2.4.3 or later.