Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Apr 18, 2008 |
| Centos_linux | — | Upgrade python-develUpgrade python-toolsUpgrade tkinterUpgrade python | Dec 1, 2016 | Apr 18, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Apr 18, 2008 |
| Oracle_linux | — | Upgrade python-toolsUpgrade pythonUpgrade tkinterUpgrade python-devel | Oct 16, 2024 | Apr 18, 2008 |
| Suse | — | Upgrade python-gdbmUpgrade python-doc-pdfUpgrade python-mpzUpgrade python-tkUpgrade python-32bitUpgrade pythonUpgrade python-idleUpgrade python-xmlUpgrade python-demoUpgrade python-x86Upgrade python-develUpgrade python-cursesUpgrade suse-releaseUpgrade python-docUpgrade python-64bit | Feb 17, 2015 | Apr 18, 2008 |
| Ubuntu | — | Upgrade python2.4Upgrade python2.5Upgrade python2.5-minimalUpgrade python2.4-minimal | Nov 8, 2024 | Apr 18, 2008 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESX 3.5 to build number 226117 | Sep 2, 2010 | Apr 18, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub