CVE-2017-1000158
17.11.2017, 05:29
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)Enginsight
Vendor | Product | Version |
---|---|---|
python | python | 𝑥 < 2.7.15 |
python | python | 3.4.0 ≤ 𝑥 < 3.4.8 |
python | python | 3.5.0 ≤ 𝑥 < 3.5.5 |
debian | debian_linux | 7.0 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
python2.7 |
| ||||||||||||||||||||||||||||
python3.4 |
| ||||||||||||||||||||||||||||
python3.5 |
| ||||||||||||||||||||||||||||
python3.6 |
| ||||||||||||||||||||||||||||
python3.7 |
|
References