[Forgot Password]
Login  Register Subscribe

24128

 
 

131573

 
 

110139

 
 

909

 
 

85964

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2010-1450Date: (C)2010-05-27   (M)2018-06-11


Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : CVSS Score : 7.5
Exploit Score: Exploit Score: 10.0
Impact Score: Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: Access Vector: NETWORK
Attack Complexity: Access Complexity: LOW
Privileges Required: Authentication: NONE
User Interaction: Confidentiality: PARTIAL
Scope: Integrity: PARTIAL
Confidentiality: Availability: PARTIAL
Integrity:  
Availability:  
  
Reference:
BID-40365
SECUNIA-42888
SECUNIA-43068
SECUNIA-43364
ADV-2011-0122
ADV-2011-0212
ADV-2011-0413
APPLE-SA-2010-11-10-1
MDVSA-2010:215
RHSA-2011:0027
RHSA-2011:0260
SUSE-SR:2011:002
http://bugs.python.org/issue8678
http://support.apple.com/kb/HT4435
https://bugzilla.redhat.com/show_bug.cgi?id=541698

CPE    1
cpe:/a:python:python:2.5
CWE    1
CWE-119
OVAL    6
oval:org.secpod.oval:def:4709
oval:org.secpod.oval:def:17194
oval:org.secpod.oval:def:4729
oval:org.secpod.oval:def:300220
...

© SecPod Technologies