Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1887

Опубликовано: 18 апр. 2008
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
Версия до 2.5.2 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*
Конфигурация 3
cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02485
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-120

Связанные уязвимости

ubuntu
около 17 лет назад

Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.

redhat
около 17 лет назад

Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.

debian
около 17 лет назад

Python 2.5.2 and earlier allows context-dependent attackers to execute ...

github
около 3 лет назад

Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.

oracle-oval
почти 16 лет назад

ELSA-2009-1176: python security update (MODERATE)

EPSS

Процентиль: 85%
0.02485
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-120