Upstream information

CVE-2008-1887 at MITRE

Description

Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having critical severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 9.3
Vector AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entry: 379534 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise SDK 10 SP2
  • python-demo >= 2.4.2-18.22
  • python-devel >= 2.4.2-18.22
  • python-doc >= 2.4.2-18.19
  • python-doc-pdf >= 2.4.2-18.19
  • python-idle >= 2.4.2-18.22
sles10-sp2.x86
sle10-sp2-sdk.x86
core9.ia64
sle10-sp2-sdk.s390x
sles9-oes.x86
sled10.x86
sles9-nlpos.x86
sles10.ia64
sles10-sp2.ia64
sled10-sp2.x86
sles9-nld.x86
sles10-sp2.x86-64
sle10-sp2-sdk.x86-64
core9.ppc
sled10.x86-64
sle10-sp2-sdk.ia64
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sles9-nld.x86-64
sle10-sp1-sdk.x86
sles10-sp2.s390x
sles10-sp2.ppc
core9.x86-64
sles10.ppc
sles10.s390x
sle10-sp2-sdk.ppc
sles10.x86
sles10.x86-64
sle10-sp1-sdk.ppc
sled10-sp2.x86-64
core9.x86
core9.s390
core9.s390x
sle10-sp1-sdk.ia64
ZYPP Patch Nr: 5490
Novell Linux Desktop 9 for x86
Open Enterprise Server
  • python >= 2.3.3-88.24
  • python-curses >= 2.3.3-88.24
  • python-demo >= 2.3.3-88.24
  • python-devel >= 2.3.3-88.24
  • python-doc >= 2.3.3-88.24
  • python-doc-pdf >= 2.3.3-88.24
  • python-gdbm >= 2.3.3-88.24
  • python-idle >= 2.3.3-88.24
  • python-mpz >= 2.3.3-88.24
  • python-tk >= 2.3.3-88.24
  • python-xml >= 2.3.3-88.24
sles10-sp2.x86
sle10-sp2-sdk.x86
core9.ia64
sle10-sp2-sdk.s390x
sles9-oes.x86
sled10.x86
sles9-nlpos.x86
sles10.ia64
sles10-sp2.ia64
sled10-sp2.x86
sles9-nld.x86
sles10-sp2.x86-64
sle10-sp2-sdk.x86-64
core9.ppc
sled10.x86-64
sle10-sp2-sdk.ia64
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sles9-nld.x86-64
sle10-sp1-sdk.x86
sles10-sp2.s390x
sles10-sp2.ppc
core9.x86-64
sles10.ppc
sles10.s390x
sle10-sp2-sdk.ppc
sles10.x86
sles10.x86-64
sle10-sp1-sdk.ppc
sled10-sp2.x86-64
core9.x86
core9.s390
core9.s390x
sle10-sp1-sdk.ia64
ZYPP Patch Nr: 5490
Novell Linux Desktop 9 for x86_64
  • python >= 2.3.3-88.24
  • python-32bit >= 9-200808010009
  • python-curses >= 2.3.3-88.24
  • python-demo >= 2.3.3-88.24
  • python-devel >= 2.3.3-88.24
  • python-doc >= 2.3.3-88.24
  • python-doc-pdf >= 2.3.3-88.24
  • python-gdbm >= 2.3.3-88.24
  • python-idle >= 2.3.3-88.24
  • python-mpz >= 2.3.3-88.24
  • python-tk >= 2.3.3-88.24
  • python-xml >= 2.3.3-88.24
sles10-sp2.x86
sle10-sp2-sdk.x86
core9.ia64
sle10-sp2-sdk.s390x
sles9-oes.x86
sled10.x86
sles9-nlpos.x86
sles10.ia64
sles10-sp2.ia64
sled10-sp2.x86
sles9-nld.x86
sles10-sp2.x86-64
sle10-sp2-sdk.x86-64
core9.ppc
sled10.x86-64
sle10-sp2-sdk.ia64
sle10-sp1-sdk.x86-64
sle10-sp1-sdk.s390x
sles9-nld.x86-64
sle10-sp1-sdk.x86
sles10-sp2.s390x
sles10-sp2.ppc
core9.x86-64
sles10.ppc
sles10.s390x
sle10-sp2-sdk.ppc
sles10.x86
sles10.x86-64
sle10-sp1-sdk.ppc
sled10-sp2.x86-64
core9.x86
core9.s390
core9.s390x
sle10-sp1-sdk.ia64
ZYPP Patch Nr: 5490
openSUSE 11.0
  • python-debuginfo >= 2.5.2-26.2
  • python-debugsource >= 2.5.2-26.2
openSUSE 11.0
  • python >= 2.5.2-26.2
  • python-32bit >= 2.5.2-26.2
  • python-64bit >= 2.5.2-26.2
  • python-curses >= 2.5.2-26.2
  • python-demo >= 2.5.2-26.2
  • python-devel >= 2.5.2-26.2
  • python-gdbm >= 2.5.2-26.2
  • python-idle >= 2.5.2-26.2
  • python-tk >= 2.5.2-26.2
  • python-xml >= 2.5.2-26.2