Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.
2018-03-07T14:29:00.280
2024-11-21T03:39:40.980
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | python | python | < 3.4.9 | Yes |
Application | python | python | < 3.5.6 | Yes |
Application | python | python | < 3.6.5 | Yes |
Application | python | python | 3.7.0 | Yes |
Application | python | python | 3.7.0 | Yes |
Application | python | python | 3.7.0 | Yes |
Application | python | python | 3.7.0 | Yes |
Application | python | python | 3.7.0 | Yes |
Operating System | microsoft | windows | * | No |