peter bassill · operator
$ cve CVE-2021-3177 JSON

CVE-2021-3177

9.8
CRITICAL · CVSS 3.1 · EPSS 23.3% (pctl 98)

Patch early

EPSS 23.3% — above the 10% action threshold.

Description

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS23.29% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-120
On CISA KEVno
Public exploitnone known
Published2021-01-19
Last modified2026-06-17

Affected (10)

VendorProduct
debiandebian linux
fedoraprojectfedora
netappactive iq unified manager
netappontap select deploy administration utility
oraclecommunications cloud native core network function cloud native environment
oraclecommunications offline mediation controller
oraclecommunications pricing design center
oracleenterprise manager ops center
oraclezfs storage appliance kit
pythonpython

References

→ the Explorer  ·  watch your stack  ·  NVD