VDB
BIT-python-min-2021-3177
BIT-python-min-2021-3177
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
Risk Scores
CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | python-min | 0, 3.7.0, 3.8.0 |
Timeline
- Jan 17, 2025 CVE Published
- Aug 11, 2025 CVE Updated
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD/ url
- https://security.netapp.com/advisory/ntap-20210226-0003/ url
- https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html url
- https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4/ url
- https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC/ url
- https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html url
- https://www.oracle.com/security-alerts/cpuoct2021.html url
- https://bugs.python.org/issue42938 url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O/ url
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO/ url
- https://www.oracle.com//security-alerts/cpujul2021.html url
- https://github.com/python/cpython/pull/24239 url
- https://www.oracle.com/security-alerts/cpujan2022.html url
- https://nvd.nist.gov/vuln/detail/CVE-2021-3177 url
…and 9 more