SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-4965

Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the…

MEDIUM 5.8EPSS 14.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
EPSS
13.95% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
python/python
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.