The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Aug 28, 2015 | May 27, 2010 |
| Apple Osx Python | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Dec 16, 2011 | May 27, 2010 |
| Centos_linux | — | Upgrade tkinterUpgrade pythonUpgrade python-docsUpgrade python-toolsUpgrade python-devel | Dec 1, 2016 | May 27, 2010 |
| Debian | — | Upgrade python2.7 | Jul 30, 2024 | May 27, 2010 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | May 27, 2010 |
| Oracle_linux | — | Upgrade python-develUpgrade python-toolsUpgrade python-libsUpgrade pythonUpgrade tkinter | Oct 16, 2024 | May 27, 2010 |
| Redhat_linux | — | No solution exists | Jul 16, 2026 | Jan 11, 2010 |
| Suse | — | Upgrade python-cursesUpgrade python-baseUpgrade python-base-x86Upgrade python-demoUpgrade python-idleUpgrade libpython2_6-1_0-32bitUpgrade libpython2_6-1_0Upgrade pythonUpgrade python-x86Upgrade libpython2_6-1_0-x86Upgrade python-base-32bitUpgrade python-tkUpgrade python-xmlUpgrade python-gdbmUpgrade python-32bit | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade python2.4-minimalUpgrade python3.1-minimalUpgrade python2.4Upgrade python2.5-minimalUpgrade python2.5Upgrade python2.6-minimalUpgrade python2.6Upgrade python3.1 | Nov 8, 2024 | May 27, 2010 |
| Vmsa 2012 0001 | — | Upgrade VMware ESXi 4.1 to build number 582267Upgrade VMware ESXi 4.0 to build number 660575Upgrade VMware ESXi 5.0 to build number 608089 | Feb 3, 2012 | May 27, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub