CVE-2007-4965
28Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendepss 12%
da publicação à arma0 dias
Publicada no NVD18 de set.
1ª PoC17 de set.
probabilidade de exploração
12%top 4% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.
Produtos afetados
n/a · n/aPoCs públicas encontradas — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/30592⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://bugs.gentoo.org/show_bug.cgi?id=192876http://docs.info.apple.com/article.html?artnum=307179http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2009/Feb/msg00000.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000005.htmlhttp://secunia.com/advisories/26837http://secunia.com/advisories/27460http://secunia.com/advisories/27562http://secunia.com/advisories/27872http://secunia.com/advisories/28136