Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2007-4965

MEDIUM severity · CVSS 5.8 · Integer overflow
5.8CVSS MEDIUM

Summary

Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.

Impact & exploitability

Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impact—
Exploit probability (EPSS)12%

AV:N/AC:M/Au:N/C:P/I:N/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.