id: PYSEC-2021-112 details: An integer overflow exists in pywin32 prior to version b301 when adding an access control entry (ACE) to an access control list (ACL) that would cause the size to be greater than 65535 bytes. An attacker who successfully exploited this vulnerability could crash the vulnerable process. affected: - package: name: pywin32 ecosystem: PyPI purl: pkg:pypi/pywin32 ranges: - type: ECOSYSTEM events: - introduced: '0' - fixed: '301' versions: - '210' - '214' - '222' - '223' - '224' - '225' - '226' - '227' - '228' - '300' references: - type: WEB url: https://github.com/mhammond/pywin32/releases - type: WEB url: https://github.com/fireeye/Vulnerability-Disclosures/blob/master/FEYE-2021-0017/FEYE-2021-0017.md - type: ADVISORY url: https://github.com/advisories/GHSA-hwfp-hg2m-9vr2 aliases: - CVE-2021-32559 - GHSA-hwfp-hg2m-9vr2 modified: '2021-07-08T03:14:30.948663Z' published: '2021-07-06T12:15:00Z'