CVE-2007-2052 describes an off-by-one error in the PyLocale_strxfrm function within Python versions 2.4 and 2.5, specifically in Modules/_localemodule.c. This flaw leads to an incorrect buffer size being used for the strxfrm function, enabling context-dependent attackers to read portions of memory due to a buffer over-read caused by missing null termination. With a CVSS score of 5.0 (Medium), this vulnerability allows for information disclosure (C:P) with low attack complexity and no authentication required. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-30018) confirms the existence of a remote information leak exploit for Python 2.5, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.4.0CPE matchmatch criteria | cpe:2.3:a:python:python:2.4.0:*:*:*:*:*:*:* | ||
2.5.0CPE matchmatch criteria | cpe:2.3:a:python:python:2.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.