Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicode string processing, related to the unicode_resize function and the PyMem_RESIZE macro.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Aug 1, 2008 |
| Centos_linux | — | Upgrade tkinterUpgrade pythonUpgrade python-develUpgrade python-tools | Dec 1, 2016 | Aug 1, 2008 |
| Freebsd | — | Upgrade python23Upgrade python24Upgrade python25 | Dec 10, 2025 | Sep 10, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Aug 1, 2008 |
| Oracle_linux | — | Upgrade python-develUpgrade pythonUpgrade python-toolsUpgrade tkinter | Oct 16, 2024 | Aug 1, 2008 |
| Suse | — | Upgrade python-idleUpgrade python-develUpgrade python-demoUpgrade python-cursesUpgrade python-gdbmUpgrade python-baseUpgrade python-32bitUpgrade python-tkUpgrade python-xmlUpgrade pythonUpgrade libpython2_7-1_0Upgrade python-x86 | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade python2.4-minimalUpgrade python2.5-minimalUpgrade python2.4Upgrade python2.5 | Nov 8, 2024 | Aug 1, 2008 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 3.5 to build number 226117Upgrade VMware ESX 4.0 to build number 208167 | Sep 2, 2010 | Aug 1, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub