PYSEC-2021-112
Dashboard / Vulnerabilities / PYSEC-2021-112
PYSEC-2021-112
Published: 6 Jul 2021Last Modified: 8 Nov 2023
Aliases:
Summary:
Details: An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.
References: https://github.com/mhammond/pywin32/releases, https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0017/FEYE-2021-0017.md, https://github.com/advisories/GHSA-hwfp-hg2m-9vr2
Affected packages
Package
Name: pywin32
Purl: pkg:pypi/pywin32
Affected ranges
Type: ECOSYSTEM
Events:
Introduced- 0
Fixed -301
Affected versions
210
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
