CVE-2007-2052
Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the...
- Published
- Apr 16, 2007
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- May 8, 2007
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:NModerate · next 30 days
- Percentile
- 96.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.
Sources
1Piotr Engelking · linux · May 8, 2007
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.