PT-2008-3807 · Python+1 · Python+1

David Remahl

·

Published

2008-08-01

·

Updated

2024-06-15

·

CVE-2008-2316

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Python versions prior to 2.5.2
Description: The issue is related to an integer overflow in the hashlib module, specifically in the hashopenssl.c file. This could potentially allow attackers to defeat cryptographic digests in certain contexts, particularly when dealing with data that exceeds 4GB.
Recommendations: For versions prior to 2.5.2, update to a version that includes the fix for the integer overflow in the hashlib module to prevent potential exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2316
DSA-1977-1
DTSA-157-1
OPENSUSE-SU-2024:11202-1
PSF-2008-5
SUSE-SU-2020:0234-1

Affected Products

Python
Suse