Oval Definition:oval:org.mitre.oval:def:8152
Revision Date:2014-06-23Version:19
Title:DSA-1551 python2.4 -- several vulnerabilities
Description:Several vulnerabilities have been discovered in the interpreter for the Python language. The Common Vulnerabilities and Exposures project identifies the following problems: Piotr Engelking discovered that the strxfrm() function of the locale module miscalculates the length of an internal buffer, which may result in a minor information disclosure. It was discovered that several integer overflows in the imageop module may lead to the execution of arbitrary code, if a user is tricked into processing malformed images. This issue is also tracked as CVE-2008-1679 due to an initially incomplete patch. Justin Ferguson discovered that a buffer overflow in the zlib module may lead to the execution of arbitrary code. Justin Ferguson discovered that insufficient input validation in PyString_FromStringAndSize() may lead to the execution of arbitrary code.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2007-2052
CVE-2007-4965
CVE-2008-1679
CVE-2008-1721
CVE-2008-1887
DSA-1551
Platform(s):Debian GNU/Linux 4.0
Product(s):python2.4
Definition Synopsis
  • Debian GNU/Linux 4.0 is installed.
  • AND Architecture section
  • Architecture independent section
  • Installed architecture is all
  • AND Packages section
  • python2.4-examples is earlier than 2.4.4-3+etch1
  • OR idle-python2.4 is earlier than 2.4.4-3+etch1
  • OR Architecture dependent section
  • Supported architectures section
  • Installed architecture is s390
  • OR Installed architecture is amd64
  • OR Installed architecture is arm
  • OR Installed architecture is i386
  • OR Installed architecture is mips
  • OR Installed architecture is ia64
  • OR Installed architecture is alpha
  • OR Installed architecture is powerpc
  • OR Installed architecture is mipsel
  • OR Installed architecture is hppa
  • AND Packages section
  • python2.4-minimal is earlier than 2.4.4-3+etch1
  • OR python2.4 is earlier than 2.4.4-3+etch1
  • OR python2.4-dbg is earlier than 2.4.4-3+etch1
  • OR python2.4-dev is earlier than 2.4.4-3+etch1
  • BACK