Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Apr 10, 2008 |
| Centos_linux | — | Upgrade pythonUpgrade python-toolsUpgrade python-develUpgrade tkinter | Dec 1, 2016 | Apr 10, 2008 |
| Freebsd | — | Upgrade python24Upgrade python25Upgrade python23 | Dec 10, 2025 | Apr 25, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Apr 10, 2008 |
| Oracle_linux | — | Upgrade python-develUpgrade python-toolsUpgrade tkinterUpgrade python | Oct 16, 2024 | Apr 10, 2008 |
| Suse | — | Upgrade python-cursesUpgrade python-xmlUpgrade python-32bitUpgrade python-develUpgrade python-gdbmUpgrade python-demoUpgrade python-x86Upgrade libpython2_7-1_0Upgrade python-baseUpgrade pythonUpgrade python-idleUpgrade python-tk | Aug 9, 2024 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python2.5-minimalUpgrade python2.4-minimalUpgrade python2.4Upgrade python2.5 | Nov 8, 2024 | Apr 10, 2008 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESX 3.5 to build number 226117 | Sep 2, 2010 | Apr 10, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub