CVE-2008-1887
18.04.2008, 17:05
Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.
| Vendor | Product | Version |
|---|---|---|
| python | python | 𝑥 ≤ 2.5.2 |
| canonical | ubuntu_linux | 6.06 |
| canonical | ubuntu_linux | 7.04 |
| canonical | ubuntu_linux | 7.10 |
| canonical | ubuntu_linux | 8.04 |
| debian | debian_linux | 4.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References