7.5
CVSSv2

CVE-2017-1000158

Published: 17/11/2017 Updated: 16/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python python

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

Vendor Advisories

Multiple security issues were discovered in Python: ElementTree failed to initialise Expat's hash salt, two denial of service issues were found in difflib and poplib and a buffer overflow in PyString_DecodeEscape For the stable distribution (stretch), these problems have been fixed in version 353-1+deb9u1 We recommend that you upgrade your pyth ...
Python could be made to run arbitrary code ...
Python could be made to run arbitrary code ...
Python could be made to run arbitrary code ...
Integer overflow in PyString_DecodeEscape results in heap-base buffer overflowCPython (aka Python) is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobjectc, resulting in heap-based buffer overflow (and possible arbitrary code execution) (CVE-2017-1000158) ...
CPython (aka Python) is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobjectc, resulting in heap-based buffer overflow (and possible arbitrary code execution) (CVE-2017-1000158) ...
CPython (aka Python) up to 2713 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobjectc, resulting in heap-based buffer overflow (and possible arbitrary code execution) ...