Lucene search

K
cve[email protected]CVE-2008-5031
HistoryNov 10, 2008 - 4:15 p.m.

CVE-2008-5031

2008-11-1016:15:12
CWE-189
web.nvd.nist.gov
80
cve-2008-5031
python
integer overflow
security vulnerability
nvd
cve-2008-2315

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%

Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c. NOTE: this vulnerability reportedly exists because of an incomplete fix for CVE-2008-2315.

Affected configurations

NVD
Node
pythonpythonMatch2.2.3
OR
pythonpythonMatch2.3.7
OR
pythonpythonMatch2.4.6
OR
pythonpythonMatch2.5.1

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.0%