My Oracle Support Banner

Python 2.7.5 Remote Code Execution Vulnerability (Doc ID 2888892.1)

Last updated on DECEMBER 06, 2022

Applies to:

Enterprise Manager Base Platform - Version 13.4.0.0.0 and later
Information in this document applies to any platform.

Goal


Python 2.7.5 version is installed on Oracle Enterprise Manager 13.4 & 13.5 which is lead to multiple Security Vulnerabilities, including CVE-2014-1912 (CVSS 7.5) unauthenticated remote code execution.

CVE-2014-1912 Description:
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.3.4, and 3.4.x before 3.4rc1 allows remote attackers to execute arbitrary code via a crafted string.

Solution

To view full details, sign in with your My Oracle Support account.

Don't have a My Oracle Support account? Click to get started!


In this Document
Goal
Solution


My Oracle Support provides customers with access to over a million knowledge articles and a vibrant support community of peers and Oracle experts.