PT-2008-3264 · Jean Loup Gailly Mark Adler+3 · Zlib+3

Published

2008-04-10

·

Updated

2024-06-15

·

CVE-2008-1721

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Python versions 2.5.2 and earlier
Description The issue is related to an integer signedness error in the zlib extension module, which allows remote attackers to execute arbitrary code via a negative signed integer. This triggers insufficient memory allocation and a buffer overflow.
Recommendations For Python versions 2.5.2 and earlier, update to a version that includes a fix for the integer signedness error in the zlib extension module. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1721
DSA-1551-1
DSA-1620-1
OPENSUSE-SU-2024:11202-1
PSF-2008-2
RHSA-2009:1176
RHSA-2009:1177
RHSA-2009_1176
RHSA-2009_1177
SUSE-SU-2020:0234-1

Affected Products

Python
Red Hat
Suse
Zlib