Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2011-006 | Aug 28, 2015 | May 27, 2010 |
| Apple Osx Python | — | Apply OS X security update 2011-006Upgrade macOS to the latest version | Dec 16, 2011 | May 27, 2010 |
| Centos_linux | — | Upgrade python-develUpgrade python-docsUpgrade python-toolsUpgrade pythonUpgrade tkinter | Dec 1, 2016 | May 27, 2010 |
| Debian | — | Upgrade python2.7 | Jul 30, 2024 | May 27, 2010 |
| Gentoo Linux | — | Upgrade dev-lang/python. | Oct 30, 2017 | May 27, 2010 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.1.0.0.24.2 on Solaris 11.1 | May 29, 2017 | May 27, 2010 |
| Oracle_linux | — | Upgrade python-toolsUpgrade tkinterUpgrade pythonUpgrade python-libsUpgrade python-devel | Oct 16, 2024 | May 27, 2010 |
| Redhat_linux | — | No solution exists | Jul 16, 2026 | May 10, 2010 |
| Suse | — | Upgrade python-32bitUpgrade python-gdbmUpgrade sap-aio-releaseUpgrade libpython2_6-1_0-32bitUpgrade python-64bitUpgrade python-base-x86Upgrade python-develUpgrade libpython2_6-1_0Upgrade python-demoUpgrade python-x86Upgrade python-base-32bitUpgrade pythonUpgrade python-cursesUpgrade python-xmlUpgrade python-baseUpgrade libpython2_6-1_0-x86Upgrade python-tkUpgrade python-idle | Feb 17, 2015 | May 27, 2010 |
| Ubuntu | — | Upgrade python2.6Upgrade python2.6-minimalUpgrade python2.5-minimalUpgrade python3.1Upgrade python2.4-minimalUpgrade python3.1-minimalUpgrade python2.5Upgrade python2.4 | Nov 8, 2024 | May 27, 2010 |
| Vmsa 2012 0001 | — | Upgrade VMware ESXi 4.1 to build number 582267Upgrade VMware ESXi 5.0 to build number 608089Upgrade VMware ESXi 4.0 to build number 660575 | Feb 3, 2012 | May 27, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub