CVE-2008-3142
published 2008-08-01CVE-2008-3142: Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.49%
90.5th percentile
Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicode string processing, related to the unicode_resize function and the PyMem_RESIZE macro.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| python | python | < 2.4.6 | 2.4.6 |
| python | python | >= 2.5.0 < 2.5.3 | 2.5.3 |
| vmware | esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_vcenter_server | — | — |
| vmware | vmware_vsphere | — | — |
| vmware | vmware_workstation | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
vendor_ubuntu6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
vendor_vmware·2009-11-20·CVSS 5.0
CVE-2007-2052 [MEDIUM] VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
VMSA-2009-0016: VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.
a. JRE Security Update JRE update to version 1.5.0_20, which addresses multiple security issues that existed in earlier releases of JRE. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095, CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the following names to the security issues fixed in JRE 1.5.0_20: CVE-2009-
Ubuntu
Python vulnerabilities
vendor_ubuntu·2008-08-01·CVSS 6.8
CVE-2008-1679 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Python vulnerabilities
It was discovered that there were new integer overflows in the imageop
module. If an attacker were able to trick a Python application into
processing a specially crafted image, they could execute arbitrary code
with user privileges. (CVE-2008-1679)
Justin Ferguson discovered that the zlib module did not correctly
handle certain archives. If an attacker were able to trick a Python
application into processing a specially crafted archive file, they could
execute arbitrary code with user privileges. (CVE-2008-1721)
Justin Ferguson discovered that certain string manipulations in Python
could be made to overflow. If an attacker were able to pass a specially
crafted string through the PyString_FromStringAndSize function, they
could
Red Hat
python: Multiple buffer overflows in unicode processing
vendor_redhat·2008-04-11·CVSS 7.5
CVE-2008-3142 [HIGH] python: Multiple buffer overflows in unicode processing
python: Multiple buffer overflows in unicode processing
Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicode string processing, related to the unicode_resize function and the PyMem_RESIZE macro.
GHSA
GHSA-p7xr-j3cg-2w5r: Multiple buffer overflows in Python 2
ghsa_unreviewed·2022-05-01
CVE-2008-3142 [HIGH] CWE-119 GHSA-p7xr-j3cg-2w5r: Multiple buffer overflows in Python 2
Multiple buffer overflows in Python 2.5.2 and earlier on 32bit platforms allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a long string that leads to incorrect memory allocation during Unicode string processing, related to the unicode_resize function and the PyMem_RESIZE macro.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=232137http://bugs.python.org/file10825/issue2620-gps02-patch.txthttp://bugs.python.org/issue2620http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlhttp://secunia.com/advisories/31305http://secunia.com/advisories/31332http://secunia.com/advisories/31358http://secunia.com/advisories/31365http://secunia.com/advisories/31473http://secunia.com/advisories/31518http://secunia.com/advisories/31687http://secunia.com/advisories/32793http://secunia.com/advisories/33937http://secunia.com/advisories/37471http://security.gentoo.org/glsa/glsa-200807-16.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289http://support.apple.com/kb/HT3438http://wiki.rpath.com/Advisories:rPSA-2008-0243http://www.debian.org/security/2008/dsa-1667http://www.mandriva.com/security/advisories?name=MDVSA-2008:163http://www.mandriva.com/security/advisories?name=MDVSA-2008:164http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900http://www.securityfocus.com/archive/1/495445/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/30491http://www.ubuntu.com/usn/usn-632-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2008/2288http://www.vupen.com/english/advisories/2009/3316https://exchange.xforce.ibmcloud.com/vulnerabilities/44170https://exchange.xforce.ibmcloud.com/vulnerabilities/44173https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11466https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8422http://bugs.gentoo.org/show_bug.cgi?id=232137http://bugs.python.org/file10825/issue2620-gps02-patch.txthttp://bugs.python.org/issue2620http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlhttp://secunia.com/advisories/31305http://secunia.com/advisories/31332http://secunia.com/advisories/31358http://secunia.com/advisories/31365http://secunia.com/advisories/31473http://secunia.com/advisories/31518http://secunia.com/advisories/31687http://secunia.com/advisories/32793http://secunia.com/advisories/33937http://secunia.com/advisories/37471http://security.gentoo.org/glsa/glsa-200807-16.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289http://support.apple.com/kb/HT3438http://wiki.rpath.com/Advisories:rPSA-2008-0243http://www.debian.org/security/2008/dsa-1667http://www.mandriva.com/security/advisories?name=MDVSA-2008:163http://www.mandriva.com/security/advisories?name=MDVSA-2008:164http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900http://www.securityfocus.com/archive/1/495445/100/0/threadedhttp://www.securityfocus.com/archive/1/507985/100/0/threadedhttp://www.securityfocus.com/bid/30491http://www.ubuntu.com/usn/usn-632-1http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlhttp://www.vupen.com/english/advisories/2008/2288http://www.vupen.com/english/advisories/2009/3316https://exchange.xforce.ibmcloud.com/vulnerabilities/44170https://exchange.xforce.ibmcloud.com/vulnerabilities/44173https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11466https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8422
2008-08-01
Published