First published: Mon May 10 2010(Updated: )
Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python | <0:2.3.4-14.9.el4 | 0:2.3.4-14.9.el4 |
redhat/python | <0:2.4.3-43.el5 | 0:2.4.3-43.el5 |
Python Babel Localedata | =2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1450 is classified as having a moderate severity due to the potential for remote code execution via crafted image files.
To fix CVE-2010-1450, upgrade Python to a version after 2.5 that addresses this buffer overflow issue.
CVE-2010-1450 affects Python versions 2.5.0 and earlier, particularly the rgbimg module.
Yes, CVE-2010-1450 can be exploited by remote attackers through the use of specially crafted image files.
Yes, CVE-2010-1450 is associated with the Python packages specifically in Red Hat versions for EL4 and EL5.