{"api_version":"1","generated_at":"2026-07-23T08:35:16+00:00","cve":"CVE-2010-1450","urls":{"html":"https://cve.report/CVE-2010-1450","api":"https://cve.report/api/cve/CVE-2010-1450.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-1450","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-1450"},"summary":{"title":"CVE-2010-1450","description":"Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.","state":"PUBLISHED","assigner":"redhat","published_at":"2010-05-27 19:30:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-120","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/43068","name":"http://secunia.com/advisories/43068","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"SUSE update for Multiple Packages - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.apple.com/kb/HT4435","name":"http://support.apple.com/kb/HT4435","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About the security content of Mac OS X v10.6.5 and Security Update 2010-007","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html","name":"http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"APPLE-SA-2010-11-10-1 Mac OS X v10.6.5 and Security Update 2010-007","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0413","name":"http://www.vupen.com/english/advisories/2011/0413","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0212","name":"http://www.vupen.com/english/advisories/2011/0212","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/43364","name":"http://secunia.com/advisories/43364","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Alerts - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0027.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0027.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support | Red Hat","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html","name":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2011:002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/40365","name":"http://www.securityfocus.com/bid/40365","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Python 'rgbimg' RLE Decoder Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Support / Security / Advisories /  / MDVSA-2010:215 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2011/0122","name":"http://www.vupen.com/english/advisories/2011/0122","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0260.html","name":"http://www.redhat.com/support/errata/RHSA-2011-0260.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/42888","name":"http://secunia.com/advisories/42888","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Red Hat update for python - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.python.org/issue8678","name":"http://bugs.python.org/issue8678","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Issue 8678: crashers in rgbimg - Python tracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=541698","name":"https://bugzilla.redhat.com/show_bug.cgi?id=541698","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"],"title":"Bug 541698 – CVE-2009-4134 CVE-2010-1449 CVE-2010-1450 python: rgbimg: multiple security issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-1450","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1450","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"1450","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"python","cpe5":"python","cpe6":"2.5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T01:21:19.173Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"43068","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43068"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.apple.com/kb/HT4435"},{"name":"ADV-2011-0212","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0212"},{"name":"43364","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/43364"},{"name":"ADV-2011-0413","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0413"},{"name":"APPLE-SA-2010-11-10-1","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html"},{"name":"ADV-2011-0122","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2011/0122"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=541698"},{"name":"SUSE-SR:2011:002","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"42888","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42888"},{"name":"40365","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/40365"},{"name":"RHSA-2011:0027","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0027.html"},{"name":"MDVSA-2010:215","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.python.org/issue8678"},{"name":"RHSA-2011:0260","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0260.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-05-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-11-18T10:00:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"43068","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43068"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.apple.com/kb/HT4435"},{"name":"ADV-2011-0212","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0212"},{"name":"43364","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/43364"},{"name":"ADV-2011-0413","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0413"},{"name":"APPLE-SA-2010-11-10-1","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2010//Nov/msg00000.html"},{"name":"ADV-2011-0122","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2011/0122"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=541698"},{"name":"SUSE-SR:2011:002","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html"},{"name":"42888","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42888"},{"name":"40365","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/40365"},{"name":"RHSA-2011:0027","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0027.html"},{"name":"MDVSA-2010:215","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:215"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.python.org/issue8678"},{"name":"RHSA-2011:0260","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2011-0260.html"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2010-1450","datePublished":"2010-05-27T19:00:00.000Z","dateReserved":"2010-04-15T00:00:00.000Z","dateUpdated":"2024-08-07T01:21:19.173Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-05-27 19:30:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-120","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:python:python:2.5.0:*:*:*:*:*:*:*","matchCriteriaId":"690CBE11-2D97-4D59-A21C-2AC388E67273"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"1450","Ordinal":"1","Title":"CVE-2010-1450","CVE":"CVE-2010-1450","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"1450","Ordinal":"1","NoteData":"Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.","Type":"Description","Title":"CVE-2010-1450"},{"CveYear":"2010","CveId":"1450","Ordinal":"2","NoteData":"2010-05-27","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"1450","Ordinal":"3","NoteData":"2010-11-18","Type":"Other","Title":"Modified"}]}}}