Skip to content

Type confusion in partial_setstate and partial_repr leads to control flow hijack #70132

@NedWilliamson

Description

@NedWilliamson
BPO 25944
Nosy @vadmium, @serhiy-storchaka
Superseder
  • bpo-25945: Type confusion in partial_setstate and partial_call leads to memory corruption
  • Files
  • partialpoc.py
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = None
    closed_at = <Date 2015-12-25.11:13:07.174>
    created_at = <Date 2015-12-25.04:12:40.085>
    labels = ['extension-modules', 'type-crash']
    title = 'Type confusion in partial_setstate and partial_repr leads to control flow hijack'
    updated_at = <Date 2016-01-03.06:42:42.674>
    user = 'https://bugs.python.org/NedWilliamson'

    bugs.python.org fields:

    activity = <Date 2016-01-03.06:42:42.674>
    actor = 'serhiy.storchaka'
    assignee = 'none'
    closed = True
    closed_date = <Date 2015-12-25.11:13:07.174>
    closer = 'serhiy.storchaka'
    components = ['Extension Modules']
    creation = <Date 2015-12-25.04:12:40.085>
    creator = 'Ned Williamson'
    dependencies = []
    files = ['41409']
    hgrepos = []
    issue_num = 25944
    keywords = []
    message_count = 4.0
    messages = ['256975', '256986', '257392', '257401']
    nosy_count = 3.0
    nosy_names = ['martin.panter', 'serhiy.storchaka', 'Ned Williamson']
    pr_nums = []
    priority = 'normal'
    resolution = 'duplicate'
    stage = 'resolved'
    status = 'closed'
    superseder = '25945'
    type = 'crash'
    url = 'https://bugs.python.org/issue25944'
    versions = ['Python 3.5', 'Python 3.6']

    Metadata

    Metadata

    Assignees

    No one assigned

      Labels

      extension-modulesC modules in the Modules dirtype-crashA hard crash of the interpreter, possibly with a core dump

      Projects

      No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions