Description
Off-by-one error in the PyLocale_strxfrm function in Modules/_localemodule.c for Python 2.4 and 2.5 causes an incorrect buffer size to be used for the strxfrm function, which allows context-dependent attackers to read portions of memory via unknown manipulations that trigger a buffer over-read due to missing null termination.
Published: 2007-04-16
Score: 5.0 Medium
EPSS: 13.7% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-1551-1 New python2.4 packages fix several vulnerabilities
Debian DSA Debian DSA DSA-1620-1 New python2.5 packages fix several vulnerabilities
Ubuntu USN Ubuntu USN USN-585-1 Python vulnerabilities
References
Link Providers
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=416934 cve-icon cve-icon
http://lists.vmware.com/pipermail/security-announce/2008/000005.html cve-icon cve-icon
http://secunia.com/advisories/25190 cve-icon cve-icon
http://secunia.com/advisories/25217 cve-icon cve-icon
http://secunia.com/advisories/25233 cve-icon cve-icon
http://secunia.com/advisories/25353 cve-icon cve-icon
http://secunia.com/advisories/25787 cve-icon cve-icon
http://secunia.com/advisories/28027 cve-icon cve-icon
http://secunia.com/advisories/28050 cve-icon cve-icon
http://secunia.com/advisories/29032 cve-icon cve-icon
http://secunia.com/advisories/29303 cve-icon cve-icon
http://secunia.com/advisories/29889 cve-icon cve-icon
http://secunia.com/advisories/31255 cve-icon cve-icon
http://secunia.com/advisories/31492 cve-icon cve-icon
http://secunia.com/advisories/37471 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1551 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1620 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDKSA-2007:099 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_13_sr.html cve-icon cve-icon
http://www.python.org/download/releases/2.5.1/NEWS.txt cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-1076.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-1077.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2008-0629.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/469294/30/6450/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/488457/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/507985/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/23887 cve-icon cve-icon
http://www.trustix.org/errata/2007/0019/ cve-icon cve-icon
http://www.ubuntu.com/usn/usn-585-1 cve-icon cve-icon
http://www.vmware.com/security/advisories/VMSA-2009-0016.html cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/1465 cve-icon cve-icon
http://www.vupen.com/english/advisories/2008/0637 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/3316 cve-icon cve-icon
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=235093 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/34060 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1358 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-2052 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11716 cve-icon cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8353 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-2052 cve-icon
History

No history.

Subscriptions

Python Python
Redhat Enterprise Linux Network Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T13:23:50.498Z

Reserved: 2007-04-16T00:00:00.000Z

Link: CVE-2007-2052

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-04-16T22:19:00.000

Modified: 2026-04-23T00:35:47.467

Link: CVE-2007-2052

cve-icon Redhat

Severity : Low

Publid Date: 2007-04-02T00:00:00Z

Links: CVE-2007-2052 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses