CVE-2007-4965
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of servi… (CVE-2007-4965)
noneEPSS 14%
Description
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.
Metrics
Severity
none
57.79
no public PoC known
96.3 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Published
2007-09-18 22:00 UTC
—
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
python
python2.5.1
References & sources
- https://bugs.python.org/issue1179report
- http://bugs.python.org/issue8678web
- http://seclists.org/fulldisclosure/2007/Sep/279web
- https://bugzilla.redhat.com/show_bug.cgi?id=541698web
- http://lists.vmware.com/pipermail/security-announce/2008/000005.htmlmailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/25696vdb-entryx_refsource_BID
- http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0254x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2007/4238vdb-entryx_refsource_VUPEN
- http://secunia.com/advisories/38675third-party-advisoryx_refsource_SECUNIA
- http://www.us-cert.gov/cas/techalerts/TA07-352A.htmlthird-party-advisoryx_refsource_CERT
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8496vdb-entrysignaturex_refsource_OVAL
- http://secunia.com/advisories/33937third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28136third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/37471third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27460third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28480third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/26837third-party-advisoryx_refsource_SECUNIA
- http://www.vupen.com/english/advisories/2007/3201vdb-entryx_refsource_VUPEN
- http://www.debian.org/security/2008/dsa-1551vendor-advisoryx_refsource_DEBIAN
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlx_refsource_CONFIRM
IDCVE-2007-4965