Описание
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | not-affected  | 2.7.12-3 | 
| devel | DNE  | |
| disco | not-affected  | 2.7.12-3 | 
| eoan | not-affected  | 2.7.12-3 | 
| esm-apps/focal | not-affected  | 2.7.12-3 | 
| esm-apps/jammy | not-affected  | 2.7.12-3 | 
| esm-infra-legacy/trusty | released  | 2.7.6-8ubuntu0.3 | 
| esm-infra/bionic | not-affected  | 2.7.12-3 | 
| esm-infra/xenial | released  | 2.7.12-1ubuntu0~16.04.1 | 
| focal | not-affected  | 2.7.12-3 | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| disco | DNE  | |
| eoan | DNE  | |
| esm-infra-legacy/trusty | DNE  | |
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| groovy | DNE  | |
| hirsute | DNE  | |
| impish | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| disco | DNE  | |
| eoan | DNE  | |
| esm-infra-legacy/trusty | released  | 3.4.3-1ubuntu1~14.04.5 | 
| esm-infra/focal | DNE  | |
| focal | DNE  | |
| groovy | DNE  | |
| hirsute | DNE  | |
| impish | DNE  | 
Показывать по
| Релиз | Статус | Примечание | 
|---|---|---|
| bionic | DNE  | |
| devel | DNE  | |
| disco | DNE  | |
| eoan | DNE  | |
| esm-infra-legacy/trusty | released  | 3.5.2-2ubuntu0~16.04.4~14.04.1 | 
| esm-infra/focal | DNE  | |
| esm-infra/xenial | released  | 3.5.2-2ubuntu0~16.04.1 | 
| focal | DNE  | |
| groovy | DNE  | |
| hirsute | DNE  | 
Показывать по
10 Critical
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
Integer overflow in the get_data function in zipimport.c in CPython (a ...
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
ELSA-2016-2586: python security, bug fix, and enhancement update (LOW)
10 Critical
CVSS2
9.8 Critical
CVSS3