CVE-2008-1721

Modified
Published: 10 Apr 2008, 19:00
Last modified:07 Aug 2024, 08:32

Vulnerability Summary

Overall Risk (default)
medium
46/100
CVSS Score
7.5 HIGH
v2.0 (nvd)
EPSS Score
28.41% HIGH
28% probability -2.67%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

10 Apr 2008, 19:00
Published
Vulnerability first disclosed
07 Aug 2024, 08:32
Last Modified
Vulnerability information updated

Description

Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.

CVSS Metrics

  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 28.41% Percentile: 97%

Techniques & Countermeasures

  • CWE-681Incorrect Conversion between Numeric Types

    When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Affected Systems

  • canonicalubuntu_linux

    6.06 | 7.04 | 7.10 | 8.04

  • debiandebian_linux

    4.0

  • pythonpython

    ≥ 2.4.0, < 2.4.6 | ≥ 2.5.0, ≤ 2.5.2

References (33)