bugs.gentoo.orgConfirmation
http://bugs.gentoo.org/show_bug.cgi?id=192876 CVE-2007-4965
Python 2.2 ImageOP Module - Multiple Integer Overflow Vulnerabilities
Record summary
CVE-2007-4965 has a selected CVSS score of 5.8; EIP currently links 1 catalogued exploit.
Description
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBPython 2.2 ImageOP Module - Multiple Integer Overflow VulnerabilitiesExploitDB exploitby Slythers BroNot analyzed1 file
References
Showing 12 of 50docs.info.apple.comConfirmation
http://docs.info.apple.com/article.html?artnum=307179 APPLE-SA-2007-12-17Vendor advisory
http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html APPLE-SA-2009-02-12Vendor advisory
http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html 20070916 python <= 2.5.1 standart librairy multiples int overflow, heap overflow in imageop modulemailing list
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.html SUSE-SR:2008:003Vendor advisory
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html [Security-announce] 20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updatesmailing list
http://lists.vmware.com/pipermail/security-announce/2008/000005.html 26837Third-party advisory
http://secunia.com/advisories/26837 27460Third-party advisory
http://secunia.com/advisories/27460 27562Third-party advisory
http://secunia.com/advisories/27562 27872Third-party advisory
http://secunia.com/advisories/27872 28136Third-party advisory
http://secunia.com/advisories/28136