Lucene search

K
ubuntuUbuntuUSN-806-1
HistoryJul 23, 2009 - 12:00 a.m.

Python vulnerabilities

2009-07-2300:00:00
ubuntu.com
47

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.3

Confidence

High

EPSS

0.012

Percentile

85.0%

Releases

  • Ubuntu 8.10
  • Ubuntu 8.04
  • Ubuntu 6.06

Packages

  • python2.4 -
  • python2.5 -

Details

It was discovered that Python incorrectly handled certain arguments in the
imageop module. If an attacker were able to pass specially crafted
arguments through the crop function, they could execute arbitrary code with
user privileges. For Python 2.5, this issue only affected Ubuntu 8.04 LTS.
(CVE-2008-4864)

Multiple integer overflows were discovered in Python’s stringobject and
unicodeobject expandtabs method. If an attacker were able to exploit these
flaws they could execute arbitrary code with user privileges or cause
Python applications to crash, leading to a denial of service.
(CVE-2008-5031)

OSVersionArchitecturePackageVersionFilename
Ubuntu8.10noarchpython2.4-minimal<Β 2.4.5-5ubuntu1.1UNKNOWN
Ubuntu8.10noarchpython2.4<Β 2.4.5-5ubuntu1.1UNKNOWN
Ubuntu8.10noarchpython2.4<Β dbg-2.4.5-5ubuntu1.1UNKNOWN
Ubuntu8.10noarchpython2.4<Β dev-2.4.5-5ubuntu1.1UNKNOWN
Ubuntu8.10noarchpython2.4<Β minimal-2.4.5-5ubuntu1.1UNKNOWN
Ubuntu8.04noarchpython2.5-minimal<Β 2.5.2-2ubuntu6UNKNOWN
Ubuntu8.04noarchpython2.5<Β 2.5.2-2ubuntu6UNKNOWN
Ubuntu8.04noarchpython2.5-dbg<Β 2.5.2-2ubuntu6UNKNOWN
Ubuntu8.04noarchpython2.5-dev<Β 2.5.2-2ubuntu6UNKNOWN
Ubuntu8.04noarchpython2.4-minimal<Β 2.4.5-1ubuntu4.2UNKNOWN
Rows per page:
1-10 of 201

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.3

Confidence

High

EPSS

0.012

Percentile

85.0%