Vulnerability Description
Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Python | Python | 2.5.0 |
Related Weaknesses (CWE)
References
- http://bugs.python.org/issue8678PatchVendor Advisory
- http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlThird Party Advisory
- http://secunia.com/advisories/42888Broken Link
- http://secunia.com/advisories/43068Broken Link
- http://secunia.com/advisories/43364Broken Link
- http://support.apple.com/kb/HT4435Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2010:215Broken Link
- http://www.redhat.com/support/errata/RHSA-2011-0027.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2011-0260.htmlThird Party Advisory
- http://www.securityfocus.com/bid/40365Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2011/0122Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0212Third Party Advisory
- http://www.vupen.com/english/advisories/2011/0413Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=541698Issue TrackingPatch
FAQ
What is CVE-2010-1450?
CVE-2010-1450 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper pr...
How severe is CVE-2010-1450?
CVE-2010-1450 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-1450?
Check the references section above for vendor advisories and patch information. Affected products include: Python Python.