CVE-2008-4864 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 21% (pctl 97)
Patch early
A public exploit exists.
Description
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer overflow, a different vulnerability than CVE-2007-4965 and CVE-2008-1679.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 21.02% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-11-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| python | python |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Python < 2.5.2 Imageop Module - 'imageop.crop()' Buffer Overflow | 2009-11-24 |
| exploit-db | Python 2.5.2 - 'Imageop' Module Argument Validation Buffer Overflow | 2008-10-27 |
References
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html
- http://scary.beasts.org/security/CESA-2008-008.html
- http://secunia.com/advisories/33937
- http://secunia.com/advisories/37471
- http://support.apple.com/kb/HT3438
- http://svn.python.org/view/python/trunk/Modules/imageop.c?rev=66689&view=diff&r1=66689&r2=66688&p1=python/trunk/Modules/imageop.c&p2=/python/trunk/Modules/imageop.c
- http://svn.python.org/view?rev=66689&view=rev
- http://www.openwall.com/lists/oss-security/2008/10/27/2
- http://www.openwall.com/lists/oss-security/2008/10/29/3
- http://www.securityfocus.com/archive/1/507985/100/0/threaded
- http://www.securityfocus.com/bid/31932
- http://www.securityfocus.com/bid/31976
- http://www.vmware.com/security/advisories/VMSA-2009-0016.html
- http://www.vupen.com/english/advisories/2009/3316
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46606
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10702
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8354
- http://lists.apple.com/archives/security-announce/2009/Feb/msg00000.html
- http://scary.beasts.org/security/CESA-2008-008.html
- http://secunia.com/advisories/33937
→ the Explorer · watch your stack · NVD