CVE-2008-4864

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
01/11/2008
Last modified:
21/11/2024

Description

Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer overflow, a different vulnerability than CVE-2007-4965 and CVE-2008-1679.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 1.5.2 (including) 2.4.6 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.3 (excluding)


References to Advisories, Solutions, and Tools