CVE-2008-1887
18.04.2008, 17:05
Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.
Vendor | Product | Version |
---|---|---|
python | python | 𝑥 ≤ 2.5.2 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 7.04 |
canonical | ubuntu_linux | 7.10 |
canonical | ubuntu_linux | 8.04 |
debian | debian_linux | 4.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References