PT-2016-6609 · Python+5 · Cpython+5

Published

2016-06-22

·

Updated

2025-09-29

·

CVE-2016-5636

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CPython versions prior to 2.7.12 CPython versions 3.x prior to 3.4.5 CPython versions 3.5.x prior to 3.5.2
Description The issue is related to an integer overflow in the get data function, which can be triggered by a negative data size value. This leads to a heap-based buffer overflow, potentially allowing remote attackers to have an unspecified impact.
Recommendations For versions prior to 2.7.12, update to version 2.7.12 or later. For versions 3.x prior to 3.4.5, update to version 3.4.5 or later. For versions 3.5.x prior to 3.5.2, update to version 3.5.2 or later.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2017-2501
ALT-PU-2017-2598
ALT-PU-2017-2851
CESA-2016_2586
CVE-2016-5636
DLA-1663-1
DLA-522-1
ELSA-2016-2586
MGASA-2016-0230
OPENSUSE-SU-2020:0086-1
OPENSUSE-SU-2020_0086-1
OPENSUSE-SU-2024:10193-1
OPENSUSE-SU-2024:10450-1
OPENSUSE-SU-2024:10536-1
OPENSUSE-SU-2024:11284-1
PSF-2016-7
RHSA-2016:2586
RHSA-2016_2586
SUSE-SU-2016:2106-1
SUSE-SU-2016:2653-1
SUSE-SU-2016:2859-1
SUSE-SU-2018:2408-1
SUSE-SU-2018_2408-1
SUSE-SU-2019:0223-1
SUSE-SU-2020:0114-1
SUSE-SU-2020:0234-1
USN-3134-1

Affected Products

Alt Linux
Cpython
Centos
Red Hat
Suse
Ubuntu