VulnerabilityModified
CVE-2008-1721
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
HIGH 7.5EPSS 22.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 22.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 22.62% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-681
- Affected
- python/python · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://bugs.python.org/issue2586Issue Tracking, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlMailing List, Third Party Advisory
- http://secunia.com/advisories/29889Not Applicable
- http://secunia.com/advisories/29955Not Applicable
- http://secunia.com/advisories/30872Not Applicable
- http://secunia.com/advisories/31255Not Applicable
- http://secunia.com/advisories/31358Not Applicable
- http://secunia.com/advisories/31365Not Applicable
- http://secunia.com/advisories/33937Not Applicable
- http://secunia.com/advisories/37471Not Applicable
- http://secunia.com/advisories/38675Not Applicable
- http://security.gentoo.org/glsa/glsa-200807-01.xmlThird Party Advisory
- http://securityreason.com/securityalert/3802Exploit, Third Party Advisory
- http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289Third Party Advisory
- http://support.apple.com/kb/HT3438Third Party Advisory
- http://support.avaya.com/css/P8/documents/100074697Third Party Advisory
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0149Broken Link
- http://www.debian.org/security/2008/dsa-1551Third Party Advisory
- http://www.debian.org/security/2008/dsa-1620Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:085Permissions Required
- http://www.securityfocus.com/archive/1/490690/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/28715Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1019823Broken Link, Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-632-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/1229/referencesPermissions Required
- http://www.vupen.com/english/advisories/2009/3316Permissions Required
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41748Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-2444Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.