Secunia Logo  
 
CVE Reference: CVE-2008-1679
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1679

Description:
Multiple integer overflows in imageop.c in Python before 2.5.3 allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted images that trigger heap-based buffer overflows. NOTE: this issue is due to an incomplete fix for CVE-2007-4965.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41958

UBUNTU
  http://www.ubuntu.com/usn/usn-632-1

SUSE
  http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html

SLACKWARE
  http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289

SAID
  Secunia Advisory: SA30872
  Secunia Advisory: SA31255
  Secunia Advisory: SA31358
  Secunia Advisory: SA31365
  Secunia Advisory: SA31518
  Secunia Advisory: SA29889
  Secunia Advisory: SA29955
  Secunia Advisory: SA31687

MISC
  http://bugs.python.org/msg64682

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:164
  http://www.mandriva.com/security/advisories?name=MDVSA-2008:163

GENTOO
  http://security.gentoo.org/glsa/glsa-200807-01.xml

DEBIAN
  http://www.debian.org/security/2008/dsa-1551
  http://www.debian.org/security/2008/dsa-1620

CONFIRM
  http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900
  http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0149
  http://bugs.python.org/issue1179


Return to the previous page.