CVE-2008-3143

HIGH
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c, (8) cStringIO.c, (9) cjkcodecs/multibytecodec.c, (10) datetimemodule.c, (11) md5.c, (12) rgbimgmodule.c, and (13) stropmodule.c in Modules/; (14) bufferobject.c, (15) listobject.c, and (16) obmalloc.c in Objects/; (17) Parser/node.c; and (18) asdl.c, (19) ast.c, (20) bltinmodule.c, and (21) compile.c in Python/, as addressed by "checks for integer overflows, contributed by Google."

References

http://bugs.gentoo.org/show_bug.cgi?id=232137

http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html

http://secunia.com/advisories/31332

http://secunia.com/advisories/31365

http://secunia.com/advisories/31473

http://secunia.com/advisories/31518

http://secunia.com/advisories/31687

http://secunia.com/advisories/32793

http://secunia.com/advisories/37471

http://security.gentoo.org/glsa/glsa-200807-16.xml

http://svn.python.org/view?rev=60793&view=rev

http://wiki.rpath.com/Advisories:rPSA-2008-0243

http://www.debian.org/security/2008/dsa-1667

http://www.mandriva.com/security/advisories?name=MDVSA-2008:163

http://www.mandriva.com/security/advisories?name=MDVSA-2008:164

http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900

http://www.python.org/download/releases/2.5.2/NEWS.txt

http://www.python.org/download/releases/2.6/NEWS.txt

http://www.securityfocus.com/archive/1/495445/100/0/threaded

http://www.securityfocus.com/archive/1/507985/100/0/threaded

http://www.securityfocus.com/bid/30491

http://www.ubuntu.com/usn/usn-632-1

http://www.vmware.com/security/advisories/VMSA-2009-0016.html

http://www.vupen.com/english/advisories/2008/2288

http://www.vupen.com/english/advisories/2009/3316

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7720

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8996

Details

Source: MITRE

Published: 2008-08-01

Updated: 2018-10-11

Type: CWE-189

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (22 total)

IDNameProductFamilySeverity
133259SUSE SLED15 / SLES15 Security Update : python (SUSE-SU-2020:0234-1) (BEAST) (httpoxy)NessusSuSE Local Security Checks
critical
89117VMware ESX / ESXi Multiple Vulnerabilities (VMSA-2009-0016) (remote check)NessusMisc.
critical
67898Oracle Linux 3 : python (ELSA-2009-1178)NessusOracle Linux Local Security Checks
critical
67897Oracle Linux 4 : python (ELSA-2009-1177)NessusOracle Linux Local Security Checks
critical
67896Oracle Linux 5 : python (ELSA-2009-1176)NessusOracle Linux Local Security Checks
critical
60625Scientific Linux Security Update : python for SL 4.x on i386/x86_64NessusScientific Linux Local Security Checks
critical
60624Scientific Linux Security Update : python for SL 3.0.x on i386/x86_64NessusScientific Linux Local Security Checks
critical
60622Scientific Linux Security Update : python for SL5.x i386/x86_64NessusScientific Linux Local Security Checks
critical
43771CentOS 5 : python (CESA-2009:1176)NessusCentOS Local Security Checks
critical
42870VMSA-2009-0016 : VMware vCenter and ESX update release and vMA patch release address multiple security issues in third party components.NessusVMware ESX Local Security Checks
medium
41229SuSE9 Security Update : Python (YOU Patch Number 12215)NessusSuSE Local Security Checks
high
40402RHEL 3 : python (RHSA-2009:1178)NessusRed Hat Local Security Checks
critical
40401RHEL 4 : python (RHSA-2009:1177)NessusRed Hat Local Security Checks
critical
40400RHEL 5 : python (RHSA-2009:1176)NessusRed Hat Local Security Checks
critical
40394CentOS 3 : python (CESA-2009:1178)NessusCentOS Local Security Checks
critical
40115openSUSE Security Update : python (python-128)NessusSuSE Local Security Checks
high
37212Mandriva Linux Security Advisory : python (MDVSA-2008:163)NessusMandriva Local Security Checks
critical
34823Debian DSA-1667-1 : python2.4 - several vulnerabilitiesNessusDebian Local Security Checks
high
33924openSUSE 10 Security Update : python (python-5491)NessusSuSE Local Security Checks
high
33923SuSE 10 Security Update : Python (ZYPP Patch Number 5490)NessusSuSE Local Security Checks
high
33807Ubuntu 6.06 LTS / 7.04 / 7.10 / 8.04 LTS : python2.4, python2.5 vulnerabilities (USN-632-1)NessusUbuntu Local Security Checks
critical
33782GLSA-200807-16 : Python: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high