{"api_version":"1","generated_at":"2026-07-23T18:56:50+00:00","cve":"CVE-2007-4965","urls":{"html":"https://cve.report/CVE-2007-4965","api":"https://cve.report/api/cve/CVE-2007-4965.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4965","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4965"},"summary":{"title":"CVE-2007-4965","description":"Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-18 22:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-190","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/31255","name":"http://secunia.com/advisories/31255","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Debian update for python2.5 - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2009/3316","name":"http://www.vupen.com/english/advisories/2009/3316","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.vmware.com/pipermail/security-announce/2008/000005.html","name":"http://lists.vmware.com/pipermail/security-announce/2008/000005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[Security-announce] VMSA-2008-0003 Moderate: Updated aacraid driver\n and samba and python service console updates","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200711-07.xml","name":"http://www.gentoo.org/security/en/glsa/glsa-200711-07.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  Python: User-assisted execution of arbitrary code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29032","name":"http://secunia.com/advisories/29032","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"VMware ESX Server Multiple Updates - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/488457/100/0/threaded","name":"http://www.securityfocus.com/archive/1/488457/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25696","name":"http://www.securityfocus.com/bid/25696","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Python ImageOP Module Multiple Integer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2008/0637","name":"http://www.vupen.com/english/advisories/2008/0637","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29303","name":"http://secunia.com/advisories/29303","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Ubuntu update for python - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:013","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:013","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2008:013 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29889","name":"http://secunia.com/advisories/29889","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Debian update for python - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-352A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-352A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-352A -- Apple Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00378.html","name":"https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00378.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SECURITY] Fedora 7 Update: python-2.5-14.fc7","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27872","name":"http://secunia.com/advisories/27872","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"rPath update for idle and python - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.gentoo.org/show_bug.cgi?id=192876","name":"http://bugs.gentoo.org/show_bug.cgi?id=192876","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Bug 192876 - dev-lang/python imageop multiple integer-overflows (CVE-2007-4965)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2008-0629.html","name":"http://www.redhat.com/support/errata/RHSA-2008-0629.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38675","name":"http://secunia.com/advisories/38675","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Avaya CMS Solaris Python Multiple Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://issues.rpath.com/browse/RPL-1885","name":"https://issues.rpath.com/browse/RPL-1885","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/archive/1/487990/100/0/threaded","name":"http://www.securityfocus.com/archive/1/487990/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/4238","name":"http://www.vupen.com/english/advisories/2007/4238","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report SUSE-SR:2008:003","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html","name":"http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"APPLE-SA-2007-12-17 Security Update 2007-009","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/37471","name":"http://secunia.com/advisories/37471","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"VMware ESX and vMA Update for Multiple Packages - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28480","name":"http://secunia.com/advisories/28480","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Mandriva update for python - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.info.apple.com/article.html?artnum=307179","name":"http://docs.info.apple.com/article.html?artnum=307179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Security Update 2007-009","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/28838","name":"http://secunia.com/advisories/28838","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE Update for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded","name":"http://www.securityfocus.com/archive/1/507985/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-585-1","name":"http://www.ubuntu.com/usn/usn-585-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-585-1: Python vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10804","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10804","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/3201","name":"http://www.vupen.com/english/advisories/2007/3201","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3438","name":"http://support.apple.com/kb/HT3438","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About the security content of Security Update 2009-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1620","name":"http://www.debian.org/security/2008/dsa-1620","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1620-1 python2.5","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27562","name":"http://secunia.com/advisories/27562","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Gentoo update for python - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"[Full-Disclosure] Mailing List Charter","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://support.avaya.com/css/P8/documents/100074697","name":"http://support.avaya.com/css/P8/documents/100074697","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"ASA-2010-050 (SUN 273570)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31492","name":"http://secunia.com/advisories/31492","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Red Hat Network Satellite Server Update for Solaris Client - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8486","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8486","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"APPLE-SA-2009-02-12 Security Update 2009-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0254","name":"http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0254","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Advisories:rPSA-2007-0254 - rPath Wiki","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36653","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36653","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8496","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8496","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2007-1076.html","name":"http://www.redhat.com/support/errata/RHSA-2007-1076.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27460","name":"http://secunia.com/advisories/27460","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Fedora update for python - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","name":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"VMSA-2009-0016.1","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28136","name":"http://secunia.com/advisories/28136","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33937","name":"http://secunia.com/advisories/33937","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.debian.org/security/2008/dsa-1551","name":"http://www.debian.org/security/2008/dsa-1551","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Debian -- Security Information -- DSA-1551-1 python2.4","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26837","name":"http://secunia.com/advisories/26837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Python imageop \"tovideo()\" Integer Overflow Security Issue - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:012","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:012","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2008:012 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4965","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4965","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4965","vulnerable":"1","versionEndIncluding":"2.5.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"python","cpe5":"python","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-4965","organization":"Red Hat","lastmodified":"2007-10-15","contributor":"Joshua Bressers","statementText":"Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=295971 The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw. More information regarding issue severity can be found here: http://www.redhat.com/security/updates/classification/","cve_year":"2007","cve_id":"4965","crc32":"37d7c816"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:17:27.603Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[Security-announce] 20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.vmware.com/pipermail/security-announce/2008/000005.html"},{"name":"25696","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25696"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0254"},{"name":"ADV-2007-4238","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/4238"},{"name":"38675","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38675"},{"name":"TA07-352A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-352A.html"},{"name":"oval:org.mitre.oval:def:8496","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8496"},{"name":"33937","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33937"},{"name":"28136","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28136"},{"name":"37471","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/37471"},{"name":"27460","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27460"},{"name":"28480","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28480"},{"name":"26837","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26837"},{"name":"ADV-2007-3201","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3201"},{"name":"DSA-1551","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1551"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"29303","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29303"},{"name":"oval:org.mitre.oval:def:8486","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8486"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3438"},{"name":"APPLE-SA-2009-02-12","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"27872","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27872"},{"name":"29032","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29032"},{"name":"31492","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31492"},{"name":"FEDORA-2007-2663","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00378.html"},{"name":"oval:org.mitre.oval:def:10804","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10804"},{"name":"RHSA-2008:0629","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0629.html"},{"name":"20070916 python <= 2.5.1 standart librairy multiples int overflow, heap overflow in imageop module","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.html"},{"name":"20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/488457/100/0/threaded"},{"name":"APPLE-SA-2007-12-17","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html"},{"name":"RHSA-2007:1076","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2007-1076.html"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"name":"ADV-2008-0637","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0637"},{"name":"python-imageop-bo(36653)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36653"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=192876"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.info.apple.com/article.html?artnum=307179"},{"name":"27562","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27562"},{"name":"USN-585-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-585-1"},{"name":"GLSA-200711-07","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200711-07.xml"},{"name":"MDVSA-2008:012","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:012"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/css/P8/documents/100074697"},{"name":"31255","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31255"},{"name":"20080212 FLEA-2008-0002-1 python","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/487990/100/0/threaded"},{"name":"MDVSA-2008:013","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:013"},{"name":"DSA-1620","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2008/dsa-1620"},{"name":"28838","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28838"},{"name":"SUSE-SR:2008:003","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://issues.rpath.com/browse/RPL-1885"},{"name":"ADV-2009-3316","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/3316"},{"name":"29889","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29889"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-09-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-15T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"[Security-announce] 20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.vmware.com/pipermail/security-announce/2008/000005.html"},{"name":"25696","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25696"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0254"},{"name":"ADV-2007-4238","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/4238"},{"name":"38675","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38675"},{"name":"TA07-352A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-352A.html"},{"name":"oval:org.mitre.oval:def:8496","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8496"},{"name":"33937","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33937"},{"name":"28136","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28136"},{"name":"37471","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/37471"},{"name":"27460","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27460"},{"name":"28480","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28480"},{"name":"26837","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26837"},{"name":"ADV-2007-3201","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3201"},{"name":"DSA-1551","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1551"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"29303","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29303"},{"name":"oval:org.mitre.oval:def:8486","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8486"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3438"},{"name":"APPLE-SA-2009-02-12","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"27872","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27872"},{"name":"29032","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29032"},{"name":"31492","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31492"},{"name":"FEDORA-2007-2663","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00378.html"},{"name":"oval:org.mitre.oval:def:10804","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10804"},{"name":"RHSA-2008:0629","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2008-0629.html"},{"name":"20070916 python <= 2.5.1 standart librairy multiples int overflow, heap overflow in imageop module","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.html"},{"name":"20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/488457/100/0/threaded"},{"name":"APPLE-SA-2007-12-17","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html"},{"name":"RHSA-2007:1076","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2007-1076.html"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"name":"ADV-2008-0637","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0637"},{"name":"python-imageop-bo(36653)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36653"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=192876"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.info.apple.com/article.html?artnum=307179"},{"name":"27562","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27562"},{"name":"USN-585-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-585-1"},{"name":"GLSA-200711-07","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://www.gentoo.org/security/en/glsa/glsa-200711-07.xml"},{"name":"MDVSA-2008:012","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:012"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/css/P8/documents/100074697"},{"name":"31255","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31255"},{"name":"20080212 FLEA-2008-0002-1 python","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/487990/100/0/threaded"},{"name":"MDVSA-2008:013","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:013"},{"name":"DSA-1620","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2008/dsa-1620"},{"name":"28838","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28838"},{"name":"SUSE-SR:2008:003","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://issues.rpath.com/browse/RPL-1885"},{"name":"ADV-2009-3316","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/3316"},{"name":"29889","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29889"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4965","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"[Security-announce] 20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates","refsource":"MLIST","url":"http://lists.vmware.com/pipermail/security-announce/2008/000005.html"},{"name":"25696","refsource":"BID","url":"http://www.securityfocus.com/bid/25696"},{"name":"http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0254","refsource":"CONFIRM","url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2007-0254"},{"name":"ADV-2007-4238","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/4238"},{"name":"38675","refsource":"SECUNIA","url":"http://secunia.com/advisories/38675"},{"name":"TA07-352A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-352A.html"},{"name":"oval:org.mitre.oval:def:8496","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8496"},{"name":"33937","refsource":"SECUNIA","url":"http://secunia.com/advisories/33937"},{"name":"28136","refsource":"SECUNIA","url":"http://secunia.com/advisories/28136"},{"name":"37471","refsource":"SECUNIA","url":"http://secunia.com/advisories/37471"},{"name":"27460","refsource":"SECUNIA","url":"http://secunia.com/advisories/27460"},{"name":"28480","refsource":"SECUNIA","url":"http://secunia.com/advisories/28480"},{"name":"26837","refsource":"SECUNIA","url":"http://secunia.com/advisories/26837"},{"name":"ADV-2007-3201","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3201"},{"name":"DSA-1551","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1551"},{"name":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2009-0016.html"},{"name":"29303","refsource":"SECUNIA","url":"http://secunia.com/advisories/29303"},{"name":"oval:org.mitre.oval:def:8486","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8486"},{"name":"http://support.apple.com/kb/HT3438","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT3438"},{"name":"APPLE-SA-2009-02-12","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"27872","refsource":"SECUNIA","url":"http://secunia.com/advisories/27872"},{"name":"29032","refsource":"SECUNIA","url":"http://secunia.com/advisories/29032"},{"name":"31492","refsource":"SECUNIA","url":"http://secunia.com/advisories/31492"},{"name":"FEDORA-2007-2663","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00378.html"},{"name":"oval:org.mitre.oval:def:10804","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10804"},{"name":"RHSA-2008:0629","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2008-0629.html"},{"name":"20070916 python <= 2.5.1 standart librairy multiples int overflow, heap overflow in imageop module","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065826.html"},{"name":"20080221 VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/488457/100/0/threaded"},{"name":"APPLE-SA-2007-12-17","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2007/Dec/msg00002.html"},{"name":"RHSA-2007:1076","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2007-1076.html"},{"name":"20091120 VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/507985/100/0/threaded"},{"name":"ADV-2008-0637","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0637"},{"name":"python-imageop-bo(36653)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36653"},{"name":"http://bugs.gentoo.org/show_bug.cgi?id=192876","refsource":"CONFIRM","url":"http://bugs.gentoo.org/show_bug.cgi?id=192876"},{"name":"http://docs.info.apple.com/article.html?artnum=307179","refsource":"CONFIRM","url":"http://docs.info.apple.com/article.html?artnum=307179"},{"name":"27562","refsource":"SECUNIA","url":"http://secunia.com/advisories/27562"},{"name":"USN-585-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-585-1"},{"name":"GLSA-200711-07","refsource":"GENTOO","url":"http://www.gentoo.org/security/en/glsa/glsa-200711-07.xml"},{"name":"MDVSA-2008:012","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:012"},{"name":"http://support.avaya.com/css/P8/documents/100074697","refsource":"CONFIRM","url":"http://support.avaya.com/css/P8/documents/100074697"},{"name":"31255","refsource":"SECUNIA","url":"http://secunia.com/advisories/31255"},{"name":"20080212 FLEA-2008-0002-1 python","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/487990/100/0/threaded"},{"name":"MDVSA-2008:013","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:013"},{"name":"DSA-1620","refsource":"DEBIAN","url":"http://www.debian.org/security/2008/dsa-1620"},{"name":"28838","refsource":"SECUNIA","url":"http://secunia.com/advisories/28838"},{"name":"SUSE-SR:2008:003","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html"},{"name":"https://issues.rpath.com/browse/RPL-1885","refsource":"CONFIRM","url":"https://issues.rpath.com/browse/RPL-1885"},{"name":"ADV-2009-3316","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/3316"},{"name":"29889","refsource":"SECUNIA","url":"http://secunia.com/advisories/29889"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4965","datePublished":"2007-09-18T22:00:00.000Z","dateReserved":"2007-09-18T00:00:00.000Z","dateUpdated":"2024-08-07T15:17:27.603Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-18 22:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-190","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","versionEndIncluding":"2.5.1","matchCriteriaId":"E17596CE-794B-43AF-BD92-CB3C490B3CB4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4965","Ordinal":"1","Title":"CVE-2007-4965","CVE":"CVE-2007-4965","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4965","Ordinal":"1","NoteData":"Multiple integer overflows in the imageop module in Python 2.5.1 and earlier allow context-dependent attackers to cause a denial of service (application crash) and possibly obtain sensitive information (memory contents) via crafted arguments to (1) the tovideo method, and unspecified other vectors related to (2) imageop.c, (3) rbgimgmodule.c, and other files, which trigger heap-based buffer overflows.","Type":"Description","Title":"CVE-2007-4965"},{"CveYear":"2007","CveId":"4965","Ordinal":"2","NoteData":"2007-09-18","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4965","Ordinal":"3","NoteData":"2018-10-15","Type":"Other","Title":"Modified"}]}}}