CVE-2010-1450

NameCVE-2010-1450
DescriptionMultiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severityhigh (attack range: remote)
Debian Bugs603162

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
python2.7 (PTS)jessie2.7.9-2+deb8u1fixed
jessie (security)2.7.9-2+deb8u5fixed
stretch (security), stretch2.7.13-2+deb9u3fixed
buster2.7.16-2fixed
bullseye, sid2.7.16-4fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
python2.4source(unstable)(unfixed)low
python2.5source(unstable)2.5.5-11low603162
python2.6source(unstable)(not affected)
python2.7source(unstable)(not affected)
python3.1source(unstable)(not affected)

Notes

- python3.1 <not-affected> (rgbimgmodule no longer included in source)
- python2.7 <not-affected> (rgbimgmodule no longer included in source)
- python2.6 <not-affected> (rgbimgmodule no longer included in source)
[lenny] - python2.5 <no-dsa> (Minor issue)
[lenny] - python2.4 <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems