Title : Python "PyLocale_strxfrm()" Off-by-one Arbitrary Memory Disclosure Vulnerability VUPEN ID : VUPEN/ADV-2007-1465 CVE ID : CVE-2007-2052
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-19
Technical Description
A vulnerability has been identified in Python, which could be exploited by attackers to gain knowledge of potentially sensitive information. This issue is caused by an off-by-one error in the "PyLocale_strxfrm()" [Modules/_localemodule.c] function when calculating the "n2" buffer size, which could be exploited by attackers to disclose and read portions of memory.