{"api_version":"1","generated_at":"2026-07-23T22:22:19+00:00","cve":"CVE-2008-2316","urls":{"html":"https://cve.report/CVE-2008-2316","api":"https://cve.report/api/cve/CVE-2008-2316.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-2316","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-2316"},"summary":{"title":"CVE-2008-2316","description":"Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to \"partial hashlib hashing of data exceeding 4GB.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2008-08-01 14:41:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-189","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289","name":"http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"The Slackware Linux Project: Slackware Security Advisories","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31687","name":"http://secunia.com/advisories/31687","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE Update for Multiple Packages - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report SUSE-SR:2008:017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/30491","name":"http://www.securityfocus.com/bid/30491","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Python Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://bugs.gentoo.org/show_bug.cgi?id=230640","name":"http://bugs.gentoo.org/show_bug.cgi?id=230640","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Bug 230640 - dev-lang/python <2.4.4-r14 integer overflows (CVE-2008-2315, CVE-2008-2316)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/2288","name":"http://www.vupen.com/english/advisories/2008/2288","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31305","name":"http://secunia.com/advisories/31305","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Python Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:163","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:163","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support / Security / Advisories /  / MDVSA-2008:163 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31473","name":"http://secunia.com/advisories/31473","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"rPath update for idle and python - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44174","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44174","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44173","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44173","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31358","name":"http://secunia.com/advisories/31358","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Slackware update for python - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31365","name":"http://secunia.com/advisories/31365","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Ubuntu update for python - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT3438","name":"http://support.apple.com/kb/HT3438","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About the security content of Security Update 2009-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://wiki.rpath.com/Advisories:rPSA-2008-0243","name":"http://wiki.rpath.com/Advisories:rPSA-2008-0243","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900","name":"http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support | Micro Focus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.gentoo.org/attachment.cgi?id=159422&action=view","name":"http://bugs.gentoo.org/attachment.cgi?id=159422&action=view","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"APPLE-SA-2009-02-12 Security Update 2009-001","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/495445/100/0/threaded","name":"http://www.securityfocus.com/archive/1/495445/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200807-16.xml","name":"http://security.gentoo.org/glsa/glsa-200807-16.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Gentoo Linux Documentation\n--\n  Python: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33937","name":"http://secunia.com/advisories/33937","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Apple Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31518","name":"http://secunia.com/advisories/31518","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE update for python - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/31332","name":"http://secunia.com/advisories/31332","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Gentoo update for python - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ubuntu.com/usn/usn-632-1","name":"http://www.ubuntu.com/usn/usn-632-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-632-1: Python vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-2316","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-2316","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"2316","vulnerable":"1","versionEndIncluding":"2.5.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"python","cpe5":"python","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2008-2316","organization":"Red Hat","lastmodified":"2008-08-04","contributor":"Tomas Hoger","statementText":"Not vulnerable. This issue did not affect the versions of python as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5. Affected module was only introduced upstream in python 2.5.","cve_year":"2008","cve_id":"2316","crc32":"4ea911f7"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T08:58:02.058Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20080813 rPSA-2008-0243-1 idle python","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/495445/100/0/threaded"},{"name":"SUSE-SR:2008:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"ADV-2008-2288","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/2288"},{"name":"python-multiple-bo(44173)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44173"},{"name":"30491","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/30491"},{"name":"33937","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33937"},{"name":"31687","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31687"},{"name":"GLSA-200807-16","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200807-16.xml"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT3438"},{"name":"APPLE-SA-2009-02-12","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"31358","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31358"},{"name":"31332","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31332"},{"name":"USN-632-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-632-1"},{"name":"31518","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31518"},{"name":"python-hashlib-overflow(44174)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44174"},{"name":"31305","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31305"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=230640"},{"name":"31365","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31365"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900"},{"name":"31473","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/31473"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.rpath.com/Advisories:rPSA-2008-0243"},{"name":"MDVSA-2008:163","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:163"},{"name":"SSA:2008-217-01","tags":["vendor-advisory","x_refsource_SLACKWARE","x_transferred"],"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.gentoo.org/attachment.cgi?id=159422&action=view"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-07-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to \"partial hashlib hashing of data exceeding 4GB.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-11T19:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20080813 rPSA-2008-0243-1 idle python","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/495445/100/0/threaded"},{"name":"SUSE-SR:2008:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"ADV-2008-2288","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/2288"},{"name":"python-multiple-bo(44173)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44173"},{"name":"30491","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/30491"},{"name":"33937","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33937"},{"name":"31687","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31687"},{"name":"GLSA-200807-16","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200807-16.xml"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT3438"},{"name":"APPLE-SA-2009-02-12","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"31358","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31358"},{"name":"31332","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31332"},{"name":"USN-632-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-632-1"},{"name":"31518","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31518"},{"name":"python-hashlib-overflow(44174)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44174"},{"name":"31305","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31305"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=230640"},{"name":"31365","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31365"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900"},{"name":"31473","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/31473"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.rpath.com/Advisories:rPSA-2008-0243"},{"name":"MDVSA-2008:163","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:163"},{"name":"SSA:2008-217-01","tags":["vendor-advisory","x_refsource_SLACKWARE"],"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.gentoo.org/attachment.cgi?id=159422&action=view"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-2316","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to \"partial hashlib hashing of data exceeding 4GB.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20080813 rPSA-2008-0243-1 idle python","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/495445/100/0/threaded"},{"name":"SUSE-SR:2008:017","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-08/msg00006.html"},{"name":"ADV-2008-2288","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/2288"},{"name":"python-multiple-bo(44173)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44173"},{"name":"30491","refsource":"BID","url":"http://www.securityfocus.com/bid/30491"},{"name":"33937","refsource":"SECUNIA","url":"http://secunia.com/advisories/33937"},{"name":"31687","refsource":"SECUNIA","url":"http://secunia.com/advisories/31687"},{"name":"GLSA-200807-16","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200807-16.xml"},{"name":"http://support.apple.com/kb/HT3438","refsource":"CONFIRM","url":"http://support.apple.com/kb/HT3438"},{"name":"APPLE-SA-2009-02-12","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html"},{"name":"31358","refsource":"SECUNIA","url":"http://secunia.com/advisories/31358"},{"name":"31332","refsource":"SECUNIA","url":"http://secunia.com/advisories/31332"},{"name":"USN-632-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-632-1"},{"name":"31518","refsource":"SECUNIA","url":"http://secunia.com/advisories/31518"},{"name":"python-hashlib-overflow(44174)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/44174"},{"name":"31305","refsource":"SECUNIA","url":"http://secunia.com/advisories/31305"},{"name":"http://bugs.gentoo.org/show_bug.cgi?id=230640","refsource":"CONFIRM","url":"http://bugs.gentoo.org/show_bug.cgi?id=230640"},{"name":"31365","refsource":"SECUNIA","url":"http://secunia.com/advisories/31365"},{"name":"http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900","refsource":"CONFIRM","url":"http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=InfoDocument-patchbuilder-readme5032900"},{"name":"31473","refsource":"SECUNIA","url":"http://secunia.com/advisories/31473"},{"name":"http://wiki.rpath.com/Advisories:rPSA-2008-0243","refsource":"CONFIRM","url":"http://wiki.rpath.com/Advisories:rPSA-2008-0243"},{"name":"MDVSA-2008:163","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:163"},{"name":"SSA:2008-217-01","refsource":"SLACKWARE","url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.525289"},{"name":"http://bugs.gentoo.org/attachment.cgi?id=159422&action=view","refsource":"CONFIRM","url":"http://bugs.gentoo.org/attachment.cgi?id=159422&action=view"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-2316","datePublished":"2008-08-01T14:00:00.000Z","dateReserved":"2008-05-18T00:00:00.000Z","dateUpdated":"2024-08-07T08:58:02.058Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-08-01 14:41:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-189","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:*:*:*:*:*:*:*:*","versionEndIncluding":"2.5.2","matchCriteriaId":"9E0806D1-04EA-492A-8587-1886F47ECC80"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"2316","Ordinal":"1","Title":"CVE-2008-2316","CVE":"CVE-2008-2316","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"2316","Ordinal":"1","NoteData":"Integer overflow in _hashopenssl.c in the hashlib module in Python 2.5.2 and earlier might allow context-dependent attackers to defeat cryptographic digests, related to \"partial hashlib hashing of data exceeding 4GB.\"","Type":"Description","Title":"CVE-2008-2316"},{"CveYear":"2008","CveId":"2316","Ordinal":"2","NoteData":"2008-08-01","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"2316","Ordinal":"3","NoteData":"2018-10-11","Type":"Other","Title":"Modified"}]}}}