CVE-2017-1000158
Ubuntu Security Notice USN-3496-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
CPython (también conocido como Python) hasta la versión 2.7.13 es vulnerable a un desbordamiento de enteros en la función PyString_DecodeEscape en stringobject.c, lo que resulta en un desbordamiento de búfer basado en memoria dinámica (heap) y, posiblemente, la ejecución de código arbitrario.
USN-3496-1 fixed a vulnerability in Python2.7. This update provides the corresponding update for versions 3.4 and 3.5. It was discovered that Python incorrectly handled decoding certain strings. An attacker could possibly use this issue to execute arbitrary code. Various other issues were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-16 CVE Reserved
- 2017-11-17 CVE Published
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id/1039890 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2017/11/msg00035.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2017/11/msg00036.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2018/09/msg00030.html | Mailing List |
|
https://lists.debian.org/debian-lts-announce/2018/09/msg00031.html | Mailing List |
|
https://security.netapp.com/advisory/ntap-20230216-0001 |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugs.python.org/issue30657 | 2023-02-16 |
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201805-02 | 2023-02-16 | |
https://www.debian.org/security/2018/dsa-4307 | 2023-02-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | < 2.7.15 Search vendor "Python" for product "Python" and version " < 2.7.15" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | >= 3.4.0 < 3.4.8 Search vendor "Python" for product "Python" and version " >= 3.4.0 < 3.4.8" | - |
Affected
| ||||||
Python Search vendor "Python" | Python Search vendor "Python" for product "Python" | >= 3.5.0 < 3.5.5 Search vendor "Python" for product "Python" and version " >= 3.5.0 < 3.5.5" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 7.0 Search vendor "Debian" for product "Debian Linux" and version "7.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|