Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-4965

31
FAUCET Score

CVE-2007-4965 describes multiple integer overflow vulnerabilities within the imageop module of Python 2.5.1 and earlier versions. These flaws, specifically in the tovideo method and other image processing functions, can lead to heap-based buffer overflows. The vulnerability carries a CVSS score of 5.8, indicating a medium severity, and allows unauthenticated attackers to cause a denial of service (application crash) and potentially disclose sensitive memory contents with moderate attack complexity. While not listed on the KEV catalog, an exploit for this vulnerability (EDB-30592) exists on ExploitDB, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.5.1CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.8MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
12.49%
Probability of exploitation in next 30 days
EPSS Percentile
95.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-30592 · Sep 17, 2007
This CVE's current EPSS score of 0.1249 is in the 96th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: python-0:2.2.3-6.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: python-0:2.3.4-14.4.el4_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: python-0:2.4.3-24.el5_3.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn-solaris-bootstrap-0:5.0.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2Fixed in: rhn_solaris_bootstrap_5_0_2_3-0:1-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn-solaris-bootstrap-0:5.0.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 4.2 (RHEL3)Fixed in: rhn_solaris_bootstrap_5_0_2_3-0:1-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn-solaris-bootstrap-0:5.0.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.0Fixed in: rhn_solaris_bootstrap_5_0_2_3-0:1-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: rhn-solaris-bootstrap-0:5.1.1-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Network Satellite Server v 5.1Fixed in: rhn_solaris_bootstrap_5_1_1_3-0:1-0
View patch

Vendor Advisories (1)

redhatCVE-2007-4965Moderate

python imageop module heap corruption

Sep 16, 2007

References

bugs.gentoo.org / show_bug.cgi
Third Party Advisory
docs.info.apple.com / article.html
Third Party Advisory
lists.apple.com / archives/security-announce/2007/Dec/msg00002.html
Mailing List
lists.apple.com / archives/security-announce/2009/Feb/msg00000.html
Mailing List
lists.grok.org.uk / pipermail/full-disclosure/2007-September/065826.html
Exploit
lists.opensuse.org / opensuse-security-announce/2008-02/msg00003.html
Third Party Advisory
lists.vmware.com / pipermail/security-announce/2008/000005.html
Third Party Advisory
secunia.com / advisories/26837
Broken Link
secunia.com / advisories/27460
Broken Link
secunia.com / advisories/27562
Broken Link
secunia.com / advisories/27872
Broken Link
secunia.com / advisories/28136
Broken Link
secunia.com / advisories/28480
Broken Link
secunia.com / advisories/28838
Broken Link
secunia.com / advisories/29032
Broken Link
secunia.com / advisories/29303
Broken Link
secunia.com / advisories/29889
Broken Link
secunia.com / advisories/31255
Broken Link
secunia.com / advisories/31492
Broken Link
secunia.com / advisories/33937
Broken Link
secunia.com / advisories/37471
Broken Link
secunia.com / advisories/38675
Broken Link
exchange.xforce.ibmcloud.com / vulnerabilities/36653
VDB Entry
issues.rpath.com / browse/RPL-1885
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10804
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8486
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8496
Broken Link
support.apple.com / kb/HT3438
Third Party Advisory
support.avaya.com / css/P8/documents/100074697
Third Party Advisory
redhat.com / archives/fedora-package-announce/2007-October/msg00378.html
Third Party Advisory
wiki.rpath.com / wiki/Advisories:rPSA-2007-0254
Third Party Advisory
debian.org / security/2008/dsa-1551
Third Party Advisory
debian.org / security/2008/dsa-1620
Third Party Advisory
gentoo.org / security/en/glsa/glsa-200711-07.xml
Third Party Advisory
mandriva.com / security/advisories
Broken Link
mandriva.com / security/advisories
Broken Link
redhat.com / support/errata/RHSA-2007-1076.html
Third Party Advisory
redhat.com / support/errata/RHSA-2008-0629.html
Third Party Advisory
securityfocus.com / archive/1/487990/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/488457/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/507985/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/25696
ExploitThird Party AdvisoryVDB Entry
ubuntu.com / usn/usn-585-1
Third Party Advisory
us-cert.gov / cas/techalerts/TA07-352A.html
Third Party AdvisoryUS Government Resource
vmware.com / security/advisories/VMSA-2009-0016.html
Third Party Advisory
vupen.com / english/advisories/2007/3201
Broken Link
vupen.com / english/advisories/2007/4238
Broken Link
vupen.com / english/advisories/2008/0637
Broken Link
vupen.com / english/advisories/2009/3316
Broken Link