CVE-2008-2316

NameCVE-2008-2316
DescriptionInteger overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to "partial hashlib hashing of data exceeding 4GB."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-1977-1, DTSA-157-1
NVD severityhigh (attack range: remote)
Debian Bugs493797

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python2.4source(unstable)(not affected)
python2.4sourceetch2.4.4-3+etch3highDSA-1977-1
python2.4sourcelenny2.4.6-1+lenny1highDSA-1977-1
python2.5source(unstable)2.5.2-11low493797
python2.5sourceetch2.5-5+etch2highDSA-1977-1
python2.5sourcelenny2.5.2-15+lenny1highDSA-1977-1

Notes

- python2.4 <not-affected> (hashlib module introduced in python2.5)

Search for package or bug name: Reporting problems