Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.104794
Category:General
Title:Python 3.12.0 Pre-Releases Multiple UAF Vulnerabilities - Windows
Summary:Python is prone to multiple use-after-free (UAF); vulnerabilities.
Description:Summary:
Python is prone to multiple use-after-free (UAF)
vulnerabilities.

Vulnerability Insight:
The AddressSanitizer (ASAN) tool has detected multiple
heap-use-after-free errors and a segmentation fault (SEGV) in the Python interpreter. The
heap-use-after-free errors occurred in the ascii_decode and unicode_decode_utf8 functions in the
unicodeobject.c file, and the SEGV occurred in the tok_backup function in the tokenizer.c file.
Additionally, a memory leak was detected in the pystate.c file.

Affected Software/OS:
Python 3.12.0 pre-releases (e.g. alpha 7) starting from Git
commit 1ef61cf71a218c71860ff6aecf0fd51edb8b65dc and prior to d5a97074d24cd14cb2a35a2b1ad3074863cde264.

Solution:
Update to the final release of version 3.12.0 or later.

CVSS Score:
4.9

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-33595
https://github.com/python/cpython/issues/103824
https://github.com/python/cpython/pull/103993/commits/c120bc2d354ca3d27d0c7a53bf65574ddaabaf3a
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.