CVE-2017-1000158
17.11.2017, 05:29
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)Enginsight
| Vendor | Product | Version |
|---|---|---|
| python | python | 𝑥 < 2.7.15 |
| python | python | 3.4.0 ≤ 𝑥 < 3.4.8 |
| python | python | 3.5.0 ≤ 𝑥 < 3.5.5 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| python2.7 |
| ||||||||||||||||||||||||||||
| python3.4 |
| ||||||||||||||||||||||||||||
| python3.5 |
| ||||||||||||||||||||||||||||
| python3.6 |
| ||||||||||||||||||||||||||||
| python3.7 |
|
References