Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-3144

17
FAUCET Score

CVE-2008-3144 describes multiple integer overflows in the PyOS_vsnprintf function within Python 2.5.2 and earlier versions, specifically impacting string formatting operations. This vulnerability has a CVSS score of 5.0, indicating a medium severity, and can lead to a denial of service through memory corruption or other unspecified impacts. There is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.5.2CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.07%
Probability of exploitation in next 30 days
EPSS Percentile
89.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0407 is in the 86th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: python-0:2.2.3-6.11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: python-0:2.3.4-14.7.el4_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: python-0:2.4.3-24.el5_3.6
View patch

Vendor Advisories (1)

redhatCVE-2008-3144Low

python: Potential integer underflow and overflow in the PyOS_vsnprintf C API function

Jun 2, 2008

References

bugs.gentoo.org / show_bug.cgi
Third Party Advisory
bugs.python.org / issue2588
Exploit
bugs.python.org / issue2589
Issue TrackingVendor Advisory
lists.apple.com / archives/security-announce/2009/Feb/msg00000.html
Mailing List
lists.opensuse.org / opensuse-security-announce/2008-08/msg00006.html
Third Party Advisory
secunia.com / advisories/31305
Broken Link
secunia.com / advisories/31332
Broken Link
secunia.com / advisories/31358
Broken Link
secunia.com / advisories/31365
Broken Link
secunia.com / advisories/31473
Broken Link
secunia.com / advisories/31518
Broken Link
secunia.com / advisories/31687
Broken Link
secunia.com / advisories/32793
Broken Link
secunia.com / advisories/33937
Broken Link
secunia.com / advisories/37471
Broken Link
security.gentoo.org / glsa/glsa-200807-16.xml
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/44171
VDB Entry
exchange.xforce.ibmcloud.com / vulnerabilities/44173
VDB Entry
slackware.com / security/viewer.php
Third Party Advisory
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10170
Broken Link
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7725
Broken Link
support.apple.com / kb/HT3438
Third Party Advisory
svn.python.org / view
Issue TrackingVendor Advisory
svn.python.org / view
Issue TrackingVendor Advisory
svn.python.org / view
Issue TrackingVendor Advisory
wiki.rpath.com / Advisories:rPSA-2008-0243
Third Party Advisory
debian.org / security/2008/dsa-1667
Third Party Advisory
mandriva.com / security/advisories
Broken LinkThird Party Advisory
mandriva.com / security/advisories
Broken LinkThird Party Advisory
novell.com / support/search.do
Third Party Advisory
securityfocus.com / archive/1/495445/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / archive/1/507985/100/0/threaded
Third Party AdvisoryVDB Entry
securityfocus.com / bid/30491
Third Party AdvisoryVDB Entry
ubuntu.com / usn/usn-632-1
Third Party Advisory
vmware.com / security/advisories/VMSA-2009-0016.html
Third Party Advisory
vupen.com / english/advisories/2008/2288
Broken LinkThird Party Advisory
vupen.com / english/advisories/2009/3316
Broken LinkThird Party Advisory