Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2052

29
FAUCET Score

CVE-2007-2052 describes an off-by-one error in the PyLocale_strxfrm function within Python versions 2.4 and 2.5, specifically in Modules/_localemodule.c. This flaw leads to an incorrect buffer size being used for the strxfrm function, enabling context-dependent attackers to read portions of memory due to a buffer over-read caused by missing null termination. With a CVSS score of 5.0 (Medium), this vulnerability allows for information disclosure (C:P) with low attack complexity and no authentication required. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-30018) confirms the existence of a remote information leak exploit for Python 2.5, though there is no evidence of widespread active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
2.4.0CPE matchmatch criteria
cpe:2.3:a:python:python:2.4.0:*:*:*:*:*:*:*
2.5.0CPE matchmatch criteria
cpe:2.3:a:python:python:2.5.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
12.48%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-30018 · May 8, 2007
This CVE's current EPSS score of 0.1248 is in the 95th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 2.1Fixed in: python-0:1.5.2-43.72.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: python-0:2.2.3-6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: python-0:2.3.4-14.4.el4_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: python-0:2.4.3-24.el5_3.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-solaris-bootstrap-0:5.0.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn_solaris_bootstrap_5_0_2_3-0:1-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-solaris-bootstrap-0:5.0.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn_solaris_bootstrap_5_0_2_3-0:1-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-solaris-bootstrap-0:5.0.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn_solaris_bootstrap_5_0_2_3-0:1-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: rhn-solaris-bootstrap-0:5.1.1-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: rhn_solaris_bootstrap_5_1_1_3-0:1-0
View patch

Vendor Advisories (1)

redhatCVE-2007-2052Low

python off-by-one locale.strxfrm() (possible memory disclosure)

Apr 2, 2007

References

bugs.debian.org / cgi-bin/bugreport.cgi
Third Party Advisory
lists.vmware.com / pipermail/security-announce/2008/000005.html
Third Party Advisory
bugzilla.redhat.com / bugzilla/show_bug.cgi
Issue Tracking
secunia.com / advisories/25190
Broken Link
secunia.com / advisories/25217
Broken Link
secunia.com / advisories/25233
Broken Link
secunia.com / advisories/25353
Broken Link
secunia.com / advisories/25787
Broken Link
secunia.com / advisories/28027
Broken Link
secunia.com / advisories/28050
Broken Link
secunia.com / advisories/29032
Broken Link
secunia.com / advisories/29303
Broken Link
secunia.com / advisories/29889
Broken Link
secunia.com / advisories/31255
Broken Link
secunia.com / advisories/31492
Broken Link
secunia.com / advisories/37471
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/34060
VDB Entry
issues.rpath.com / browse/RPL-1358
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11716
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8353
Broken Link
debian.org / security/2008/dsa-1551
Third Party Advisory
debian.org / security/2008/dsa-1620
Third Party Advisory
mandriva.com / security/advisories
Broken LinkThird Party Advisory
novell.com / linux/security/advisories/2007_13_sr.html
Third Party Advisory
python.org / download/releases/2.5.1/NEWS.txt
Broken LinkVendor Advisory
redhat.com / support/errata/RHSA-2007-1076.html
Third Party Advisory
redhat.com / support/errata/RHSA-2007-1077.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0629.html
Third Party Advisory
securityfocus.com / archive/1/469294/30/6450/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/488457/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/507985/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/23887
Third Party AdvisoryVDB Entry
trustix.org / errata/2007/0019
Third Party Advisory
ubuntu.com / usn/usn-585-1
Third Party Advisory
vmware.com / security/advisories/VMSA-2009-0016.html
Broken LinkThird Party Advisory
vupen.com / english/advisories/2007/1465
Broken LinkThird Party Advisory
vupen.com / english/advisories/2008/0637
Broken LinkThird Party Advisory
vupen.com / english/advisories/2009/3316
Broken LinkThird Party Advisory