Secunia
|
|

|
|
|
|
|
|
|
Release Date: 2005-02-04 Views: 13,870
Where:
From remote
Impact:
Security Bypass, Manipulation of data, Exposure of sensitive information, System access,
Solution Status:
Vendor Patch
CVE Reference(s):
Graham Dumpleton has reported a vulnerability in Python, which can be exploited by malicious people to bypass certain security restrictions.
The vulnerability is caused due to an error in the SimpleXMLRPCServer library module, where the internals of registered objects or modules are not properly protected. This may be exploited to disclose and modify sensitive information and potentially execute arbitrary code.
Successful exploitation requires that a vulnerable XML-RPC server registers an object via the "register_instance()" method without a "_dispatch()" method.
The vulnerability has been reported in all versions of 2.2, 2.3 versions prior to 2.3.5, and in version 2.4.
Solution:
Apply patches.
Further details available to Secunia VIM customers
Provided and/or discovered by:
Graham Dumpleton
Original Advisory:
http://www.python.org/security/PSF-2005-001/
Deep Links:
Links available to Secunia VIM customers
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
Subject: Python SimpleXMLRPCServer Library Module Vulnerability
|
No posts yet |
|
You must be logged in to post a comment. |
Not a customer already?Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance. |