Vulnerability Intelligence Report
CVE-2021-3177
Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:23.29%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-120 ↗CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| python | python | all |
| fedoraproject | fedora | 32, 33 |
| netapp | active_iq_unified_manager | all |
| netapp | ontap_select_deploy_administration_utility | all |
| debian | debian_linux | 9.0 |
| oracle | communications_cloud_native_core_network_function_cloud_native_environment | 22.2.0 |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
| oracle | communications_pricing_design_center | 12.0.0.3.0 |
| oracle | enterprise_manager_ops_center | 12.4.0.0 |
| oracle | zfs_storage_appliance_kit | 8.8 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
23.293%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2021-01-19T00:00:00 |
| Published | 2021-01-19T00:00:00 |
| Last Updated | 2025-12-18T15:03:34 |
Community Chatter & Buzz