Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 637938 (CVE-2017-1000158)

Summary: <dev-lang/python-2.7.14: Buffer overflow vulnerability (CVE-2017-1000158)
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: major CC: python
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://bugs.python.org/issue30657
See Also: https://bugs.gentoo.org/show_bug.cgi?id=635944
Whiteboard: A2 [glsa+ cve]
Package list:
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2017-11-17 14:52:22 UTC
CVE-2017-1000158 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000158):
  CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in
  the PyString_DecodeEscape function in stringobject.c, resulting in
  heap-based buffer overflow (and possible arbitrary code execution)
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-17 14:55:06 UTC
Refer to Bug 635944 for stabilization
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2018-05-02 23:54:50 UTC
This issue was resolved and addressed in
 GLSA 201805-02 at https://security.gentoo.org/glsa/201805-02
by GLSA coordinator Aaron Bauman (b-man).