Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
BID:28749
Info
Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
| Bugtraq ID: | 28749 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-1887 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2008 12:00AM |
| Updated: | Mar 19 2015 09:16AM |
| Credit: | Justin Ferguson and Alexander Belopolsky |
| Vulnerable: |
VMWare vMA 4.0 VMWare ESX Server 3.0.3 VMWare ESX Server 3.0.2 VMWare ESX Server 3.0.1 VMWare ESX Server 3.0 VMWare ESX Server 2.5.5 VMWare ESX Server 4.0 VMWare ESX Server 3.5 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 lpia Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 9 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE SUSE Linux Enterprise Desktop 10.SP1 SuSE SUSE Linux Enterprise Desktop 10 SP2 SuSE SUSE Linux Enterprise Desktop 10 SP1 SuSE SUSE Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE openSUSE 10.3 SuSE Linux Professional 10.2 x86_64 SuSE Linux Personal 10.2 x86_64 SuSE Linux 9 S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux Standard Server 8.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. openSUSE 11.0 S.u.S.E. openSUSE 10.2 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Desktop 10 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 2 rPath rPath Linux 1 rPath Appliance Platform Linux Service 2 rPath Appliance Platform Linux Service 1 RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux Desktop Workstation 5 client RedHat Enterprise Linux Desktop version 4 RedHat Desktop 3.0 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux AS 4 Red Hat Enterprise Linux AS 3 Red Hat Enterprise Linux 5 Server Python Software Foundation Python 2.5.2 Novell Open Enterprise Server (OES) 0 Novell Linux POS 9 Novell Linux Desktop 9 Gentoo Linux Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya Message Networking 3.1 Avaya Intuity AUDIX LX 2.0 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.4.11 Apple Mac OS X Server 10.4.10 Apple Mac OS X Server 10.4.9 Apple Mac OS X Server 10.4.8 Apple Mac OS X Server 10.4.7 Apple Mac OS X Server 10.4.6 Apple Mac OS X Server 10.4.5 Apple Mac OS X Server 10.4.4 Apple Mac OS X Server 10.4.3 Apple Mac OS X Server 10.4.2 Apple Mac OS X Server 10.4.1 Apple Mac OS X Server 10.4 Apple Mac OS X Server 10.5 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.4.11 Apple Mac OS X 10.4.10 Apple Mac OS X 10.4.9 Apple Mac OS X 10.4.8 Apple Mac OS X 10.4.7 Apple Mac OS X 10.4.6 Apple Mac OS X 10.4.5 Apple Mac OS X 10.4.4 Apple Mac OS X 10.4.3 Apple Mac OS X 10.4.2 Apple Mac OS X 10.4.1 Apple Mac OS X 10.4 Apple Mac OS X 10.5 |
| Not Vulnerable: |
VMWare vMA 4.0 Patch 2 |
Discussion
Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
Python is prone to multiple remote buffer-overflow vulnerabilities because certain functions in the core API fail to properly verify user-supplied data.
An attacker can exploit these issues to execute arbitrary code with the privileges of the user running an application that uses the affected functions. Failed exploit attempts will result in a denial-of-service condition.
This issue affects Python 2.5.2; earlier versions may also be vulnerable.
Python is prone to multiple remote buffer-overflow vulnerabilities because certain functions in the core API fail to properly verify user-supplied data.
An attacker can exploit these issues to execute arbitrary code with the privileges of the user running an application that uses the affected functions. Failed exploit attempts will result in a denial-of-service condition.
This issue affects Python 2.5.2; earlier versions may also be vulnerable.
Exploit / POC
Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
VMWare ESX Server 4.0
Apple Mac OS X 10.4.11
Apple Mac OS X Server 10.4.11
VMWare ESX Server 3.0.3
Solution:
Updates are available. Please see the references for more information.
VMWare ESX Server 4.0
-
VMWare ESX-4.0.0-update01.zip
https://hostupdate.vmware.com/software/VUM/OFFLINE/release-158-2009111 8-187517/ESX-4.0.0-update01.zip
Apple Mac OS X 10.4.11
-
Apple SecUpd2009-001Intel.dmg
for Intel
http://support.apple.com/downloads/Security_Update_2009_001__Tiger_Int el_ -
Apple SecUpd2009-001PPC.dmg
for PPC
http://support.apple.com/downloads/Security_Update_2009_001__Tiger_PPC _
Apple Mac OS X Server 10.4.11
-
Apple SecUpdSrvr2009-001PPC.dmg
for PPC
http://support.apple.com/downloads/Security_Update_2009_001__Server_Ti ger_PPC_ -
Apple SecUpdSrvr2009-001Univ.dmg
Universal
http://support.apple.com/downloads/Security_Update_2009_001__Server_Un iversal_
VMWare ESX Server 3.0.3
-
VMWare ESX303-201002206-UG.zip
http://download3.vmware.com/software/vi/ESX303-201002206-UG.zip
References
Python 'stringobject.c' Multiple Remote Buffer Overflow Vulnerabilities
References:
References:
- About the security content of Security Update 2009-001 (Apple)
- Issue2587: PyString_FromStringAndSize() to be considered unsafe (Python)
- Novell Advisory: Python 20080801 (Novell)
- Python Homepage (Python Software Foundation)
- IOActive Security Advisory: Incorrect input validation in PyString_FromStringAnd (Justin Ferguson
) - VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release addre (VMware Security Team
)