CVE-2018-1000117

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
07/03/2018
Last modified:
05/07/2022

Description

Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.2.0 (including) 3.4.9 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.5.0 (including) 3.5.6 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.5 (excluding)
cpe:2.3:a:python:python:3.7.0:beta1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.7.0:beta2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.7.0:beta3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.7.0:beta4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.7.0:beta5:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*