Description
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Justin Ferguson · pythonremoteunix
https://www.exploit-db.com/exploits/31634
References (33)
... and 13 more
Scores
EPSS
0.3108
EPSS Percentile
96.8%
Details
CWE
CWE-681
Status
published
Products (6)
canonical/ubuntu_linux
6.06
canonical/ubuntu_linux
7.04
canonical/ubuntu_linux
7.10
canonical/ubuntu_linux
8.04
debian/debian_linux
4.0
python/python
2.4.0 - 2.4.6
Published
Apr 10, 2008
Tracked Since
Feb 18, 2026