Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c. NOTE: this vulnerability reportedly exists because of an incomplete fix for CVE-2008-2315.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Python | — | Apply OS X security update 2009-001 | Dec 16, 2011 | Nov 10, 2008 |
| Centos_linux | — | Upgrade pythonUpgrade tkinterUpgrade python-toolsUpgrade python-devel | Dec 1, 2016 | Nov 10, 2008 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | Nov 10, 2008 |
| Oracle_linux | — | Upgrade tkinterUpgrade python-develUpgrade pythonUpgrade python-tools | Oct 16, 2024 | Nov 10, 2008 |
| Suse | — | Upgrade python-32bitUpgrade python-x86Upgrade python-tkUpgrade python-doc-pdfUpgrade python-demoUpgrade pythonUpgrade python-idleUpgrade python-xmlUpgrade python-gdbmUpgrade python-64bitUpgrade python-mpzUpgrade python-docUpgrade python-develUpgrade python-curses | Feb 17, 2015 | Nov 10, 2008 |
| Ubuntu | — | Upgrade python2.4-minimalUpgrade python2.5-minimalUpgrade python2.5Upgrade python2.4 | Nov 8, 2024 | Nov 10, 2008 |
| Vmsa 2009 0016 5 Updated Service Console Package Python | — | Upgrade VMware ESX 3.5 to build number 226117Upgrade VMware ESX 4.0 to build number 208167 | Sep 2, 2010 | Nov 10, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub