VDB
CVE-2005-0089
CVE-2005-0089
PUBLISHED
CVSS 7.5 HIGH
The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes.
EPSS 6.00% · 92.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
6.00%
92.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| python | python | 2.4.0, 0 |
Timeline
- Feb 6, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Aug 3, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 31, 2023 EPSS Score
References
- python-simplexmlrpcserver-bypass(19217) vdb
- 14128 third-party-advisory
- 2005-0003 vendor-advisory
- MDKSA-2005:035 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2005-0089 advisory
- http://marc.info/?l=bugtraq&m=110746469728728&w=2 url
- http://securitytracker.com/id?1013083 url
- http://www.debian.org/security/2005/dsa-666 url
- http://www.python.org/security/PSF-2005-001 url
- http://www.securityfocus.com/bid/12437 url
- http://www.trustix.org/errata/2005/0003 url
- http://www.python.org/security/PSF-2005-001/ technical
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9811 technical
- http://python.org/security/PSF-2005-001/patch-2.2.txt technical
- http://www.redhat.com/support/errata/RHSA-2005-108.html advisory