2008-08-01 16:41:00 2018-10-11 22:47:18

Multiple integer overflows in the PyOS_vsnprintf function in Python/mysnprintf.c in Python 2.5.2 and earlier allow context-dependent attackers to cause a denial of service (memory corruption) or have unspecified other impact via crafted input to string formatting operations. NOTE: the handling of certain integer values is also affected by related integer underflows and an off-by-one error.

Vector

NETWORK

Complexity

LOW

Authentication

NONE

Confidentiality

NONE

Integrity

NONE

Availability

PARTIAL
Python software foundation Python 2.5.2 (not an official CPE) Python software foundation Python 2.5.1 (not an official CPE) Python software foundation Python 2.5 (not an official CPE) Python software foundation Python 2.4.5 (not an official CPE) Python software foundation Python 2.4.4 (not an official CPE) Python software foundation Python 2.4.3 (not an official CPE) Python software foundation Python 2.4.2 (not an official CPE) Python software foundation Python 2.4.1 (not an official CPE) Python software foundation Python 2.4 (not an official CPE) Python software foundation Python 2.3.7 (not an official CPE) Python software foundation Python 2.3.6 (not an official CPE) Python software foundation Python 2.3.5 (not an official CPE) Python software foundation Python 2.3.4 (not an official CPE) Python software foundation Python 2.3.3 (not an official CPE) Python software foundation Python 2.3.2 (not an official CPE) Python software foundation Python 2.3.1 (not an official CPE) Python software foundation Python 2.3 (not an official CPE) Python software foundation Python 2.2.3 (not an official CPE) Python software foundation Python 2.2.2 (not an official CPE) Python software foundation Python 2.2.1 (not an official CPE) Python software foundation Python 2.2 (not an official CPE) Python software foundation Python 2.1.3 (not an official CPE) Python software foundation Python 2.1.2 (not an official CPE) Python software foundation Python 2.1.1 (not an official CPE) Python software foundation Python 2.1 (not an official CPE) Python software foundation Python 2.0.1 (not an official CPE) Python software foundation Python 2.0 (not an official CPE) Python software foundation Python 1.6.1 (not an official CPE) Python software foundation Python 1.6 (not an official CPE) Python software foundation Python 1.5.2 (not an official CPE)