Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules. NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Aug 1, 2008 |
| Centos_linux | — | Upgrade pythonUpgrade tkinterUpgrade python-toolsUpgrade python-devel | Dec 1, 2016 | Aug 1, 2008 |
| Freebsd | — | Upgrade python24Upgrade python23Upgrade python25 | Dec 10, 2025 | Sep 10, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Aug 1, 2008 |
| Oracle_linux | — | Upgrade python-toolsUpgrade python-develUpgrade pythonUpgrade tkinter | Oct 16, 2024 | Aug 1, 2008 |
| Suse | — | Upgrade python-tkUpgrade python-x86Upgrade pythonUpgrade python-baseUpgrade python-xmlUpgrade libpython2_7-1_0Upgrade python-32bitUpgrade python-gdbmUpgrade python-idleUpgrade python-develUpgrade python-demoUpgrade python-curses | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade python2.5-minimalUpgrade python2.4-minimalUpgrade python2.5Upgrade python2.4 | Nov 8, 2024 | Aug 1, 2008 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESX 3.5 to build number 226117 | Sep 2, 2010 | Aug 1, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub