Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.
The product performs a calculation that can produce an integer overflow or wraparound, when the logic assumes that the resulting value will always be larger than the original value. This can introduce other weaknesses when the calculation is used for resource management or execution control.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Python | Python | * | 2.5.1 (including) |
Red Hat Enterprise Linux 3 | RedHat | python-0:2.2.3-6.8 | * |
Red Hat Enterprise Linux 4 | RedHat | python-0:2.3.4-14.4.el4_6.1 | * |
Red Hat Enterprise Linux 5 | RedHat | python-0:2.4.3-24.el5_3.6 | * |
Red Hat Network Satellite Server v 4.2 | RedHat | rhn-solaris-bootstrap-0:5.0.2-3 | * |
Red Hat Network Satellite Server v 4.2 | RedHat | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | * |
Red Hat Network Satellite Server v 4.2 (RHEL3) | RedHat | rhn-solaris-bootstrap-0:5.0.2-3 | * |
Red Hat Network Satellite Server v 4.2 (RHEL3) | RedHat | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | * |
Red Hat Network Satellite Server v 5.0 | RedHat | rhn-solaris-bootstrap-0:5.0.2-3 | * |
Red Hat Network Satellite Server v 5.0 | RedHat | rhn_solaris_bootstrap_5_0_2_3-0:1-0 | * |
Red Hat Network Satellite Server v 5.1 | RedHat | rhn-solaris-bootstrap-0:5.1.1-3 | * |
Red Hat Network Satellite Server v 5.1 | RedHat | rhn_solaris_bootstrap_5_1_1_3-0:1-0 | * |
Python2.2 | Ubuntu | dapper | * |
Python2.3 | Ubuntu | dapper | * |
Python2.4 | Ubuntu | dapper | * |
Python2.4 | Ubuntu | edgy | * |
Python2.4 | Ubuntu | feisty | * |
Python2.4 | Ubuntu | gutsy | * |
Python2.5 | Ubuntu | edgy | * |
Python2.5 | Ubuntu | feisty | * |
Python2.5 | Ubuntu | gutsy | * |