CVE-2014-1912
Publication date 21 February 2014
Last updated 24 July 2024
Ubuntu priority
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.
Status
Package | Ubuntu Release | Status |
---|---|---|
python2.6 | 13.10 saucy | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
10.04 LTS lucid |
Fixed 2.6.5-1ubuntu6.3
|
|
python2.7 | 13.10 saucy |
Fixed 2.7.5-8ubuntu3.1
|
12.10 quantal |
Fixed 2.7.3-5ubuntu4.4
|
|
12.04 LTS precise |
Fixed 2.7.3-0ubuntu3.5
|
|
10.04 LTS lucid | Not in release | |
python3.1 | 13.10 saucy | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Ignored end of life | |
python3.2 | 13.10 saucy | Not in release |
12.10 quantal |
Fixed 3.2.3-6ubuntu3.5
|
|
12.04 LTS precise |
Fixed 3.2.3-0ubuntu3.6
|
|
10.04 LTS lucid | Not in release | |
python3.3 | 13.10 saucy |
Fixed 3.3.2-7ubuntu3.1
|
12.10 quantal |
Fixed 3.3.0-1ubuntu0.2
|
|
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release | |
python3.4 | 13.10 saucy | Not in release |
12.10 quantal | Not in release | |
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release |
Patch details
Package | Patch details |
---|---|
python2.7 | |
python3.1 | |
python3.2 | |
python3.3 |
References
Related Ubuntu Security Notices (USN)
- USN-2125-1
- Python vulnerability
- 3 March 2014