CVE-2008-5031

EUVD-2008-5010
Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c.  NOTE: this vulnerability reportedly exists because of an incomplete fix for CVE-2008-2315.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
Affected Products (NVD)
VendorProductVersion
pythonpython
2.2.3
pythonpython
2.3.7
pythonpython
2.4.6
pythonpython
2.5.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python2.4
dapper
Fixed 2.4.3-0ubuntu6.3
released
hardy
Fixed 2.4.5-1ubuntu4.2
released
intrepid
Fixed 2.4.5-5ubuntu1.1
released
jaunty
not-affected
python2.5
dapper
dne
gutsy
ignored
hardy
not-affected
intrepid
not-affected
jaunty
not-affected
Common Weakness Enumeration
References