PT-2008-4562 · Python+2 · Python+2

Published

2008-08-01

·

Updated

2024-06-15

·

CVE-2008-3143

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Python versions prior to 2.5.2
Description: The issue is related to multiple integer overflows in various Python modules and files, including Include/pymem.h, csv.c, struct.c, arraymodule.c, audioop.c, binascii.c, cPickle.c, cStringIO.c, cjkcodecs/multibytecodec.c, datetimemodule.c, md5.c, rgbimgmodule.c, stropmodule.c, bufferobject.c, listobject.c, obmalloc.c, Parser/node.c, asdl.c, ast.c, bltinmodule.c, and compile.c. These overflows might allow context-dependent attackers to have an unknown impact. The issue has been addressed by adding checks for integer overflows, contributed by Google.
Recommendations: For Python versions prior to 2.5.2, update to version 2.5.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the affected modules until a patch is available.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3143
DSA-1667-1
OPENSUSE-SU-2024:11202-1
PSF-2008-7
RHSA-2009:1176
RHSA-2009:1177
RHSA-2009:1178
RHSA-2009_1176
RHSA-2009_1177
SUSE-SU-2020:0234-1

Affected Products

Python
Red Hat
Suse