CVE-2007-4965
MEDIUM severity · CVSS 5.8 · Integer overflow
5.8CVSS MEDIUM
Summary
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impact—
Exploit probability (EPSS)12%
AV:N/AC:M/Au:N/C:P/I:N/A:P
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://bugs.gentoo.org/show_bug.cgi?id=192876Advisory
- http://docs.info.apple.com/article.html?artnum=307179Advisory
- http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlAdvisory
- http://lists.vmware.com/pipermail/security-announce/2008/000005.htmlAdvisory
- http://secunia.com/advisories/26837
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.htmlExploit