CVE-2010-1450
Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.88%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.88% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- python/python
- Source
- secalert@redhat.com
References
- http://bugs.python.org/issue8678Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/42888Broken Link
- http://secunia.com/advisories/43068Broken Link
- http://secunia.com/advisories/43364Broken Link
- http://support.apple.com/kb/HT4435Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:215Broken Link
- http://www.redhat.com/support/errata/RHSA-2011-0027.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/40365Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2011/0122Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0413Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=541698Issue Tracking, Patch
- http://bugs.python.org/issue8678Patch, Vendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/42888Broken Link
- http://secunia.com/advisories/43068Broken Link
- http://secunia.com/advisories/43364Broken Link
- http://support.apple.com/kb/HT4435Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:215Broken Link
- http://www.redhat.com/support/errata/RHSA-2011-0027.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/40365Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2011/0122Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0413Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=541698Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.