logo

Python Remote Code Execution in socket.recvfrom_into()

ID: db9b4c44-9497-56cf-9fc0-704d3023a18d

STIX ID: report--db9b4c44-9497-56cf-9fc0-704d3023a18d

Feed Name: TrustedSec blog

Threat Score
55/100

Date Published: 2023-09-20

Date Updated: 2026-05-01

...
...

This report describes a published proof-of-concept for a stack‑overflow remote code execution vulnerability in Python's socket.recvfrom_into() (affecting Python 2.7 and 3.x). The author reproduces and rewrites the exploit, provides a quick test to detect vulnerable interpreters, notes the flaw was reported and fixed (issue20246), and confirms the Artillery honeypot is not affected because it never calls recvfrom_into().

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.