CVE-2007-4965

Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of servi… (CVE-2007-4965)

Description

Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.

Metrics

Severity
none
no public PoC known
96.3 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
14.0 %
Elevated — model estimates 10-50% exploitation likelihood.
Published
2007-09-18 22:00 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • python

    python2.5.1

References & sources

IDCVE-2007-4965