CVE-2010-1449

NameCVE-2010-1449
DescriptionInteger overflow in rgbimgmodule.c in the rgbimg module in Python 2.5 allows remote attackers to have an unspecified impact via a large image that triggers a buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-3143.12.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs603162

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python2.7 (PTS)bullseye2.7.18-8+deb11u1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python2.4source(unstable)(unfixed)low
python2.5source(unstable)2.5.5-11low603162
python2.6source(unstable)(not affected)
python2.7source(unstable)(not affected)
python3.1source(unstable)(not affected)

Notes

- python3.1 <not-affected> (rgbimgmodule no longer included in source)
- python2.7 <not-affected> (rgbimgmodule no longer included in source)
- python2.6 <not-affected> (rgbimgmodule no longer included in source)
[lenny] - python2.5 <no-dsa> (Minor issue)
[lenny] - python2.4 <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems