CVE-2008-1721
10.04.2008, 19:05
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| python | python | 2.4.0 ≤ 𝑥 < 2.4.6 |
| python | python | 2.5.0 ≤ 𝑥 ≤ 2.5.2 |
| debian | debian_linux | 4.0 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
| canonical | ubuntu_linux | 8.04 |
𝑥
= Vulnerable software versions
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpython2_7-1_0 |
| ||||||||||||||||||||||||
| python |
| ||||||||||||||||||||||||
| python-base |
| ||||||||||||||||||||||||
| python-curses |
| ||||||||||||||||||||||||
| python-devel |
| ||||||||||||||||||||||||
| python-gdbm |
| ||||||||||||||||||||||||
| python-xml |
|
References