oss-sec mailing list archives

Re: CVE Request: Python 3.2/3.3 utf-16 decoder unicode_decode_call_errorhandler aligned_end is not updated


From: Henri Salo <henri () nerv fi>
Date: Wed, 25 Apr 2012 19:31:37 +0300

On Wed, Apr 25, 2012 at 12:50:55PM +0200, Florian Weimer wrote:
* Kurt Seifried:

Python 3.2/3.3 utf-16 decoder unicode_decode_call_errorhandler
aligned_end is not updated

does not appear to affect Python 2.x

3.1 seems to be affected as well (according to reproducer and commit
log).

Yes it is. I confirmed this also with Debian 3.1.3-12+squeeze1

- Henri Salo


Current thread: