CVE-2010-1634

UnknownEPSS 4.38%

Last modified

CVE-2010-1634 is a vulnerability of currently unknown severity. Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.. EPSS estimates a 4.38% chance of exploitation in the next 30 days.

Description

Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.

Metrics

EPSS Probability
4.38%

90.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
PythonPython>= 2.5.0, < 2.5.6
PythonPython>= 2.6.0, < 2.6.6
PythonPython>= 3.1.0, < 3.1.3
FedoraprojectFedora13
OpensuseOpensuse11.2
OpensuseOpensuse11.3
SuseLinux Enterprise Server10Sp3
SuseLinux Enterprise Server11
CanonicalUbuntu Linux8.04
CanonicalUbuntu Linux10.04
CanonicalUbuntu Linux11.04
CanonicalUbuntu Linux11.10

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2010-1634?
Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.
How severe is CVE-2010-1634?
Severity scoring for CVE-2010-1634 is pending analysis. The EPSS model estimates a 4.38% probability of exploitation in the next 30 days.
How do I fix CVE-2010-1634?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2010-1634?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST