Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000158

Опубликовано: 17 нояб. 2017
Источник: debian
EPSS Низкий

Описание

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.5fixed3.5.5-1package
python3.4removedpackage
python2.7fixed2.7.13-4package
python2.7fixed2.7.13-2+deb9u2stretchpackage
python2.6removedpackage

Примечания

  • https://bugs.python.org/issue30657

  • 2.7 https://github.com/python/cpython/commit/c3c9db89273fabc62ea1b48389d9a3000c1c03ae (v2.7.14rc1)

  • 3.4 https://github.com/python/cpython/commit/6c004b40f9d51872d848981ef1a18bb08c2dfc42 (v3.4.8rc1)

  • 3.5 https://github.com/python/cpython/commit/fd8614c5c5466a14a945db5b059c10c0fb8f76d9 (v3.5.5rc1)

  • The 2.7.13-4 upload included the commit in debian/patches/git-updates.diff

EPSS

Процентиль: 85%
0.02492
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 7 лет назад

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

CVSS3: 8.1
redhat
около 8 лет назад

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

CVSS3: 9.8
nvd
больше 7 лет назад

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

suse-cvrf
около 7 лет назад

Security update for python

CVSS3: 9.8
github
около 3 лет назад

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

EPSS

Процентиль: 85%
0.02492
Низкий