LWN.net Logo

python3: data leaks, memory damage, and crash

Package(s):python3 CVE #(s):CVE-2012-2135
Created:July 11, 2012 Updated:August 13, 2012
Description: From the Novell bugzilla:

In the utf-16 decoder after calling unicode_decode_call_errorhandler aligned_end is not updated. This may potentially cause data leaks, memory damage, and crash. The bug introduced by implementation of the issue #4868. In a similar situation in the utf-8 decoder aligned_end is updated.

Alerts:
openSUSE openSUSE-SU-2012:0861-1 2012-07-11
Mageia MGASA-2012-0208 2012-08-12
Ubuntu USN-1615-1 2012-10-23
Ubuntu USN-1616-1 2012-10-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds