Python socket.recvfrom_into() remote buffer overflow
pastebin.com
pastebin.com
http://bugs.python.org/review/20246/diff/10559/Modules/socke...
It appears to me that a well-written server would not be exploitable: the bug fixed here is a failure to check that the "nbytes" argument is not larger than the "buffer" argument. But nobody should have been calling this function with such erroneous arguments (ideally). Still a bad bug, but not as severe as it might sound at first.
I originally thought that this wouldn't be a big deal because using recvfrom_into is annoying, you have to make a mutable buffer object and the most immediate way I found to do that involved ctypes, which is scary. However, on perusal a bunch of code hosted on github uses recvfrom_into in vulnerable ways, so that's pretty exciting.
edit: I was mistaken, see below
/* If nbytes was not specified, use the buffer's length */
So it still seems to me that in order to be exploitable an application would need to specify a "wrong" value for nbytes, which after the patch would raise an exception. It's not a case where such code should work and instead overflows.http://bugs.python.org/issue20246
Now why aren't you posting every security bug in every language to reach HN front page?
Also, providing an exploit, rather than just the notification makes it clear how important it is to act quickly.
Don't worry, your fellow Pythonistas ensure that every Ruby security bug reaches the front page.
(I don't actually have any skin in this argument since I don't use either language but if you are going to ask such blatantly leading questions then you don't really deserve a better response.)
"Working with the exploit, its trivial to get a working remote exploit to work, below is a simple rewritten RCE from the exploit PoC": https://www.trustedsec.com/february-2014/python-remote-code-...
So if one were to insert commas in the appropriate places, it becomes “and, while very highly unlikely, it's technically remotely exploitable.”.
So the original bug report did concede that, while the bug itself is very unlikely, the bug is remotely exploitable.