u0pattern / CVE-2018-1000117-Exploit

Buffer Overflow Vulnerability that can result ACE

Home Page:http://python-security.readthedocs.io/vuln/cve-2018-1000117_buffer_overflow_vulnerability_in_os.symlink_on_windows.html

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE-2018-1000117


Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.


Vulnerable Versions

Python 2.7
Python 3.4
Python 3.5
Python 3.6

Credits

About

Buffer Overflow Vulnerability that can result ACE

http://python-security.readthedocs.io/vuln/cve-2018-1000117_buffer_overflow_vulnerability_in_os.symlink_on_windows.html


Languages

Language:Python 100.0%