CVE-2010-2089

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
27/05/2010
Last modified:
11/04/2025

Description

The audioop module in Python 2.7 and 3.2 does not verify the relationships between size arguments and byte string lengths, which allows context-dependent attackers to cause a denial of service (memory corruption and application crash) via crafted arguments, as demonstrated by a call to audioop.reverse with a one-byte string, a different vulnerability than CVE-2010-1634.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 2.5.0 (including) 2.5.6 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 2.6.0 (including) 2.6.6 (excluding)
cpe:2.3:a:python:python:*:*:*:*:*:*:*:* 3.1.0 (including) 3.1.3 (excluding)


References to Advisories, Solutions, and Tools