Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-2089

Опубликовано: 27 мая 2010
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
Версия от 2.5.0 (включая) до 2.5.6 (исключая)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
Версия от 2.6.0 (включая) до 2.6.6 (исключая)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.1.3 (исключая)

EPSS

Процентиль: 94%
0.15801
Средний

5 Medium

CVSS2

Дефекты

CWE-787

Связанные уязвимости

ubuntu
около 15 лет назад

The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

redhat
больше 15 лет назад

The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

debian
около 15 лет назад

The audioop module in Python 2.7 and 3.2 does not verify the relations ...

github
около 3 лет назад

The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

oracle-oval
больше 14 лет назад

ELSA-2011-0027: python security, bug fix, and enhancement update (LOW)

EPSS

Процентиль: 94%
0.15801
Средний

5 Medium

CVSS2

Дефекты

CWE-787