CVE-2007-4965 describes multiple integer overflow vulnerabilities within the imageop module of Python 2.5.1 and earlier versions. These flaws, specifically in the tovideo method and other image processing functions, can lead to heap-based buffer overflows. The vulnerability carries a CVSS score of 5.8, indicating a medium severity, and allows unauthenticated attackers to cause a denial of service (application crash) and potentially disclose sensitive memory contents with moderate attack complexity. While not listed on the KEV catalog, an exploit for this vulnerability (EDB-30592) exists on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.5.1CPE matchmatch criteria | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.