CVE-2023-33595

NameCVE-2023-33595
DescriptionCPython v3.12.0 alpha 7 was discovered to contain a heap use-after-free via the function ascii_decode at /Objects/unicodeobject.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python2.7 (PTS)jessie, jessie (lts)2.7.9-2-ds1-1+deb8u11fixed
stretch (security)2.7.13-2+deb9u6fixed
stretch (lts), stretch2.7.13-2+deb9u8fixed
buster2.7.16-2+deb10u1fixed
buster (security)2.7.16-2+deb10u3fixed
bullseye2.7.18-8+deb11u1fixed
python3.10 (PTS)sid3.10.13-1fixed
python3.11 (PTS)bookworm3.11.2-6fixed
trixie3.11.8-1fixed
sid3.11.8-3fixed
python3.4 (PTS)jessie, jessie (lts)3.4.2-1+deb8u15fixed
python3.5 (PTS)stretch (security)3.5.3-1+deb9u5fixed
stretch (lts), stretch3.5.3-1+deb9u8fixed
python3.7 (PTS)buster3.7.3-2+deb10u3fixed
buster (security)3.7.3-2+deb10u6fixed
python3.9 (PTS)bullseye3.9.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python2.7source(unstable)(not affected)
python3.10source(unstable)(not affected)
python3.11source(unstable)(not affected)
python3.4source(unstable)(not affected)
python3.5source(unstable)(not affected)
python3.7source(unstable)(not affected)
python3.9source(unstable)(not affected)

Notes

- python3.11 <not-affected> (Vulnerable code not present)
- python3.10 <not-affected> (Vulnerable code not present)
- python3.9 <not-affected> (Vulnerable code not present)
- python3.7 <not-affected> (Vulnerable code not present)
- python2.7 <not-affected> (Vulnerable code not present)
https://github.com/python/cpython/issues/103824
Introduced by: https://github.com/python/cpython/commit/1ef61cf71a218c71860ff6aecf0fd51edb8b65dc (v3.12.0b1)
Fixed by: https://github.com/python/cpython/commit/d5a97074d24cd14cb2a35a2b1ad3074863cde264 (v3.12.0b1)
- python3.4 <not-affected> (Vulnerable code not present)
- python3.5 <not-affected> (Vulnerable code not present)

Search for package or bug name: Reporting problems