[New-bugs-announce] [issue41189] An exploitable segmentation fault in _PyEval_EvalFrameDefault

Iman Sharafodin report at bugs.python.org
Wed Jul 1 14:03:54 EDT 2020


New submission from Iman Sharafodin <iman.sharafodin at gmail.com>:

Python 3.6 (June 27, 2020) (https://www.python.org/ftp/python/3.6.11/Python-3.6.11.tgz).

I found an exploitable segmentation fault in Python 3.6.11 (I validated that by using GDB's Exploitable plugin). Please find the attachment.

#0  0x0000000000b63bf4 in _PyEval_EvalFrameDefault (f=<optimized out>, throwflag=<optimized out>) at Python/ceval.c:3667
#1  0x0000000000b5bc5b in PyEval_EvalFrameEx (throwflag=0, f=0x7ffff7f66c50) at Python/ceval.c:754
#2  _PyEval_EvalCodeWithName (_co=_co at entry=0x7ffff7ef5030, globals=globals at entry=0x7ffff7f62168, locals=locals at entry=0x7ffff7f62168, args=args at entry=0x0, argcount=argcount at entry=0, kwnames=kwnames at entry=0x0, kwargs=0x0, kwcount=0, kwstep=2, defs=0x0, defcount=0, kwdefs=0x0, closure=0x0, name=0x0, qualname=0x0) at Python/ceval.c:4166
#3  0x0000000000b6100b in PyEval_EvalCodeEx (closure=0x0, kwdefs=0x0, defcount=0, defs=0x0, kwcount=0, kws=0x0, argcount=0, args=0x0, locals=locals at entry=0x7ffff7f62168, globals=globals at entry=0x7ffff7f62168, _co=_co at entry=0x7ffff7ef5030) at Python/ceval.c:4187
#4  PyEval_EvalCode (co=co at entry=0x7ffff7ef5030, globals=globals at entry=0x7ffff7f62168, locals=locals at entry=0x7ffff7f62168) at Python/ceval.c:731

----------
files: ExploitableCrash.pyc
messages: 372776
nosy: Iman Sharafodin
priority: normal
severity: normal
status: open
title: An exploitable segmentation fault in _PyEval_EvalFrameDefault
versions: Python 3.6
Added file: https://bugs.python.org/file49285/ExploitableCrash.pyc

_______________________________________
Python tracker <report at bugs.python.org>
<https://bugs.python.org/issue41189>
_______________________________________


More information about the New-bugs-announce mailing list