Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 











Abonnez-vous gratuitement à notre NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Se désabonner

Vigil@nce - Python : buffer overflow of rgbimg

juin 2010 par Vigil@nce

This bulletin was written by Vigil@nce : http://vigilance.fr/

SYNTHESIS OF THE VULNERABILITY

Several vulnerabilities of the rgbimg module of Python can be used
by an attacker, in order to create a denial of service or to
execute code.

Severity : 2/4

Creation date : 26/05/2010

DESCRIPTION OF THE VULNERABILITY

The rgbimg module of Python manages images. It is deprecated since
Python 2.6. It is impacted by several vulnerabilities.

When an image has a large number of channels (ZSIZE), a buffer
underflow occurs, which stops the application. [severity:1/4 ;
BID-40361, CVE-2009-4134]

A buffer overflow occurs in the PyString_FromStringAndSize()
function. [severity:2/4 ; BID-40363, CVE-2010-1449]

An attacker can generate two buffer overflows in the RLE decoder.
[severity:2/4 ; BID-40365, CVE-2010-1450]

An attacker can therefore create a denial of service or execute
code.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/Python-buffer-overflow-of-rgbimg-9667


Voir les articles précédents

    

Voir les articles suivants