Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to "partial hashlib hashing of data exceeding 4GB."
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Aug 1, 2008 |
| Freebsd | — | Upgrade python25Upgrade python23Upgrade python24 | Dec 10, 2025 | Sep 10, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Aug 1, 2008 |
| Suse | — | Upgrade python-tkUpgrade libpython2_7-1_0Upgrade python-cursesUpgrade python-gdbmUpgrade python-32bitUpgrade python-x86Upgrade pythonUpgrade python-xmlUpgrade python-develUpgrade python-baseUpgrade python-idleUpgrade python-demo | Feb 17, 2015 | Jul 9, 2013 |
| Ubuntu | — | Upgrade python2.4-minimalUpgrade python2.5Upgrade python2.5-minimalUpgrade python2.4 | Nov 8, 2024 | Aug 1, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub