CVE-2021-32559

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-32559
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-32559.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-32559
Aliases
Published
2021-07-06T12:15:21Z
Modified
2024-10-12T07:33:44.542166Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process.

References

Affected packages

Git / github.com/mhammond/pywin32

Affected ranges

Type
GIT
Repo
https://github.com/mhammond/pywin32
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

218.*

218.5

Other

ActivePython202
ActivePython210
ActivePython211
a2
adodbapi_2_1
adodbapi_2_2_2
b126
b127
b128
b129
b129f
b130
b131
b132
b134
b135
b139
b140
b141
b142
b145
b146
b147
b148
b149
b151
b153
b157
b159
b200
b201
b202
b203
b204
b205
b206
b207
b208
b209
b211
b212
b213
b214
b215
b216
b217
b218
b219
b220
b221
b222
b223
b224
b225
b226
b227
b228
b300
cvs2hg
py3k-merge-complete

b218.*

b218.3