Out-of-Bounds Read Vulnerability in typed_ast Python Library by Python Software Foundation
CVE-2019-19275
7.5HIGH
Summary
The typed_ast library versions 1.3.0 and 1.3.1 contain an out-of-bounds read issue within the ast_for_arguments function. This vulnerability arises when a Python interpreter processes Python source code, potentially leading to a crash of the interpreter process without executing the code. Such a scenario can pose challenges for web services that utilize Python code parsing. It is important for users of these specific versions to apply the necessary updates to mitigate potential disruptions.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved