Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules. NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Aug 1, 2008 |
| Centos_linux | — | Upgrade python-toolsUpgrade python-develUpgrade pythonUpgrade tkinter | Dec 1, 2016 | Aug 1, 2008 |
| Freebsd | — | Upgrade python24Upgrade python25Upgrade python23 | Dec 10, 2025 | Sep 10, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Aug 1, 2008 |
| Oracle_linux | — | Upgrade pythonUpgrade tkinterUpgrade python-develUpgrade python-tools | Oct 16, 2024 | Aug 1, 2008 |
| Suse | — | Upgrade python-demoUpgrade python-gdbmUpgrade python-idleUpgrade python-develUpgrade python-cursesUpgrade libpython2_7-1_0Upgrade python-32bitUpgrade python-tkUpgrade python-xmlUpgrade python-x86Upgrade python-baseUpgrade python | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade python2.5-minimalUpgrade python2.4-minimalUpgrade python2.5Upgrade python2.4 | Nov 8, 2024 | Aug 1, 2008 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESX 3.5 to build number 226117 | Sep 2, 2010 | Aug 1, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub