CVE-2008-4864 describes multiple integer overflows in the imageop module of Python versions 1.5.2 through 2.5.1. Specifically, large integer values supplied to the imageop.crop() function can lead to a buffer overflow, allowing attackers to escape the Python VM and execute arbitrary code. This vulnerability carries a CVSS score of 7.5, indicating a high severity with network-based exploitation, low attack complexity, and potential for partial compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, public exploit code exists on ExploitDB, though there is no evidence of active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.5.2, < 2.4.6CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* | ||
>= 2.5.0, < 2.5.3CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.