The Python Software Foundation (PSF) has released Python versions 3.9.2 and 3.8.8 to address two serious security flaws, including an RCE bug.
The PSF urges Python users to upgrade their systems to Python 3.8.8 or 3.9.2, especially to address the remote code execution (RCE) vulnerability reported as CVE-2021-3177.

The company accelerated their release after receiving unexpected pressure from some users concerned about the security flaw.
“Since the announcement of the release candidates for versions 3.9.2 and 3.8.8, we have received a number of inquiries from end users urging us to expedite the final releases due to security content, specifically CVE-2021-3177,” Python said.
Python a buffer overflow in PyCArg_repr in ctypes/callproc.c, which can lead to remote code execution.
It affects Python applications that “accept floating-point numbers as unreliable input, as seen by the 1e300 argument in c_double.from_param.”
The bug occurs because “sprintf” is used in an unsafe manner. The impact is widespread because Python is pre-installed with many Linux distributions and Windows 10.
Various Linux distributions, such as Debian, have supported security patches to ensure that built-in versions of Python are protected.
The vulnerability is a common memory flaw. According to RedHat, a stack-based buffer overflow in Python's cyypes module incorrectly validated input passed to it, "which could allow an attacker to overflow a buffer on the stack and crash the application ."
While the RCE vulnerability is indeed a very negative thing, RedHat notes that “the biggest threat from this vulnerability is system availability.” In other words, an attacker would likely be able to launch a denial of service attack.
Information source: zdnet.com
