Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules. NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Aug 1, 2008 |
| Centos_linux | — | Upgrade tkinterUpgrade pythonUpgrade python-toolsUpgrade python-devel | Dec 1, 2016 | Aug 1, 2008 |
| Freebsd | — | Upgrade python24Upgrade python23Upgrade python25 | Dec 10, 2025 | Sep 10, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Aug 1, 2008 |
| Oracle_linux | — | Upgrade tkinterUpgrade pythonUpgrade python-develUpgrade python-tools | Oct 16, 2024 | Aug 1, 2008 |
| Suse | — | Upgrade python-baseUpgrade libpython2_7-1_0Upgrade pythonUpgrade python-x86Upgrade python-xmlUpgrade python-32bitUpgrade python-tkUpgrade python-idleUpgrade python-cursesUpgrade python-gdbmUpgrade python-develUpgrade python-demo | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade python2.4Upgrade python2.5Upgrade python2.4-minimalUpgrade python2.5-minimal | Nov 8, 2024 | Aug 1, 2008 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 4.0 to build number 208167Upgrade VMware ESX 3.5 to build number 226117 | Sep 2, 2010 | Aug 1, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub