Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 637938 (CVE-2017-1000158) - <dev-lang/python-2.7.14: Buffer overflow vulnerability (CVE-2017-1000158)
Summary: <dev-lang/python-2.7.14: Buffer overflow vulnerability (CVE-2017-1000158)
Status: RESOLVED FIXED
Alias: CVE-2017-1000158
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal major (vote)
Assignee: Gentoo Security
URL: https://bugs.python.org/issue30657
Whiteboard: A2 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2017-11-17 14:52 UTC by GLSAMaker/CVETool Bot
Modified: 2018-05-02 23:54 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2017-11-17 14:52:22 UTC
CVE-2017-1000158 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-1000158):
  CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in
  the PyString_DecodeEscape function in stringobject.c, resulting in
  heap-based buffer overflow (and possible arbitrary code execution)
Comment 1 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2017-11-17 14:55:06 UTC
Refer to Bug 635944 for stabilization
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2018-05-02 23:54:50 UTC
This issue was resolved and addressed in
 GLSA 201805-02 at https://security.gentoo.org/glsa/201805-02
by GLSA coordinator Aaron Bauman (b-man).