CVE-2017-1000158
published 2017-11-17CVE-2017-1000158: CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.23%
94.3th percentile
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python2.7 | < python2.7 2.7.13-4 (bullseye) | python2.7 2.7.13-4 (bullseye) |
| python | python | < 2.7.15 | 2.7.15 |
| python | python | >= 3.4.0 < 3.4.8 | 3.4.8 |
| python | python | >= 3.5.0 < 3.5.5 | 3.5.5 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Python vulnerability
vendor_ubuntu·2017-11-28
CVE-2017-1000158 Python vulnerability
Title: Python vulnerability
Summary: Python could be made to run arbitrary code.
It was discovered that Python incorrectly handled decoding certain strings.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python vulnerability
vendor_ubuntu·2017-11-28
CVE-2017-1000158 Python vulnerability
Title: Python vulnerability
Summary: Python could be made to run arbitrary code.
USN-3496-1 fixed a vulnerability in Python2.7. This update provides
the corresponding update for versions 3.4 and 3.5.
Original advisory details:
It was discovered that Python incorrectly handled decoding certain strings.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Python vulnerability
vendor_ubuntu·2017-11-28
CVE-2017-1000158 Python vulnerability
Title: Python vulnerability
Summary: Python could be made to run arbitrary code.
USN-3496-1 fixed a vulnerability in Python. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that Python incorrectly handled decoding certain strings.
An attacker could possibly use this issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow
vendor_redhat·2017-06-13·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CWE-190 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow
python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
Statement: This issue affects the versions of python as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7, and python27-python, rh-python34-python, and rh-python35-python as shipped with Red Hat Software Collections 3. Red Hat Product Security has rated this issue as having Moderate security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package:
Debian
CVE-2017-1000158: python2.7 - CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the Py...
vendor_debian·2017·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158: python2.7 - CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the Py...
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
Scope: local
bullseye: resolved (fixed in 2.7.13-4)
GHSA
GHSA-r68f-4xcm-3xr6: CPython (aka Python) up to 2
ghsa_unreviewed·2022-05-13
CVE-2017-1000158 [CRITICAL] CWE-190 GHSA-r68f-4xcm-3xr6: CPython (aka Python) up to 2
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
OSV
CVE-2017-1000158: CPython (aka Python) up to 2
osv·2017-11-17·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158: CPython (aka Python) up to 2
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000158 python3: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
bugzilla·2017-12-01·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158 python3: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
CVE-2017-1000158 python3: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE
Bugzilla
CVE-2017-1000158 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
bugzilla·2017-12-01·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
CVE-2017-1000158 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2017-1000158 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow
bugzilla·2017-12-01·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow
CVE-2017-1000158 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow
In Python 2.7, Python 3.4 and Python 3.5 there is a possible integer overflow in PyString_DecodeEscape function of the file stringobject.c, which can be abused to gain a heap overflow, possibly leading to arbitrary code execution.
References:
https://bugs.python.org/issue30657
http://python-security.readthedocs.io/vuln/cve-2017-1000158_pystring_decodeescape_integer_overflow.html
https://github.com/python/cpython/commit/c3c9db89273fabc62ea1b48389d9a3000c1c03ae
Discussion:
Created python tracking bugs for this issue:
Affects: fedora-all [bug 1519606]
Created python26 tracking bugs for this issue:
Affects: fedora-all [bug 1519602]
Created python3 tracking bugs for this issue:
Aff
Bugzilla
CVE-2017-1000158 python34: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
bugzilla·2017-12-01·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158 python34: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
CVE-2017-1000158 python34: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2017-1000158 python35: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
bugzilla·2017-12-01·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158 python35: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
CVE-2017-1000158 python35: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2017-1000158 python26: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
bugzilla·2017-12-01·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158 python26: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
CVE-2017-1000158 python26: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2017-1000158 python33: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
bugzilla·2017-12-01·CVSS 9.8
CVE-2017-1000158 [CRITICAL] CVE-2017-1000158 python33: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
CVE-2017-1000158 python33: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
arXiv
Vulnerability Analysis of 2500 Docker Hub Images
arxiv_fulltext·2020-06-11
Vulnerability Analysis of 2500 Docker Hub Images
Vulnerability Analysis of 2500 Docker Hub Images
Katrine Wist
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
Malene Helsem
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
Danilo Gligoroski
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
## Abstract
The use of container technology has skyrocketed during the last few years, with Docker as the leading container platform. Docker's online repository for publicly available container images, called Docker Hub, hosts over 3.5 million images at the time of writing, making it the world's largest community of container images. We pe
http://www.securitytracker.com/id/1039890https://bugs.python.org/issue30657https://lists.debian.org/debian-lts-announce/2017/11/msg00035.htmlhttps://lists.debian.org/debian-lts-announce/2017/11/msg00036.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00031.htmlhttps://security.gentoo.org/glsa/201805-02https://security.netapp.com/advisory/ntap-20230216-0001/https://www.debian.org/security/2018/dsa-4307http://www.securitytracker.com/id/1039890https://bugs.python.org/issue30657https://lists.debian.org/debian-lts-announce/2017/11/msg00035.htmlhttps://lists.debian.org/debian-lts-announce/2017/11/msg00036.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00030.htmlhttps://lists.debian.org/debian-lts-announce/2018/09/msg00031.htmlhttps://security.gentoo.org/glsa/201805-02https://security.netapp.com/advisory/ntap-20230216-0001/https://www.debian.org/security/2018/dsa-4307
2017-11-17
Published