CVE-2008-2315
Last modified
CVE-2008-2315 is a vulnerability of currently unknown severity. Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules. NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.. EPSS estimates a 4.21% chance of exploitation in the next 30 days.
Description
Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules. NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Python | Python | <= 2.5.2 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=230640Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/31305Broken Link
- http://secunia.com/advisories/31332Broken Link
- http://secunia.com/advisories/31358Broken Link
- http://secunia.com/advisories/31365Broken Link
- http://secunia.com/advisories/31518Broken Link
- http://secunia.com/advisories/31687Broken Link
- http://secunia.com/advisories/32793Broken Link
- http://secunia.com/advisories/33937Broken Link
- http://secunia.com/advisories/37471Broken Link
- http://secunia.com/advisories/38675Broken Link
- http://security.gentoo.org/glsa/glsa-200807-16.xmlThird Party Advisory
- http://support.apple.com/kb/HT3438Third Party Advisory
- http://support.avaya.com/css/P8/documents/100074697Third Party Advisory
- http://www.debian.org/security/2008/dsa-1667Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:163Broken Link, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:164Broken Link, Third Party Advisory
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30491Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-632-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2288Broken Link, Third Party Advisory
- http://www.vupen.com/english/advisories/2009/3316Broken Link, Third Party Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=230640Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/31305Broken Link
- http://secunia.com/advisories/31332Broken Link
- http://secunia.com/advisories/31358Broken Link
- http://secunia.com/advisories/31365Broken Link
- http://secunia.com/advisories/31518Broken Link
- http://secunia.com/advisories/31687Broken Link
- http://secunia.com/advisories/32793Broken Link
- http://secunia.com/advisories/33937Broken Link
- http://secunia.com/advisories/37471Broken Link
- http://secunia.com/advisories/38675Broken Link
- http://security.gentoo.org/glsa/glsa-200807-16.xmlThird Party Advisory
- http://support.apple.com/kb/HT3438Third Party Advisory
- http://support.avaya.com/css/P8/documents/100074697Third Party Advisory
- http://www.debian.org/security/2008/dsa-1667Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:163Broken Link, Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:164Broken Link, Third Party Advisory
- http://www.securityfocus.com/archive/1/507985/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/30491Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-632-1Third Party Advisory
- http://www.vmware.com/security/advisories/VMSA-2009-0016.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/2288Broken Link, Third Party Advisory
- http://www.vupen.com/english/advisories/2009/3316Broken Link, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2315?
How severe is CVE-2008-2315?
How do I fix CVE-2008-2315?
Are you affected by CVE-2008-2315?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
