Python SVN commit r64114 added integer overflow checks to multiple python module: http://svn.python.org/view?view=rev&revision=64114 All the issue got covered under single CVE - CVE-2008-3143. Checks added to audioop (and rgbimg, see bug #541698) were incorrect and possible to bypass: http://bugs.python.org/issue8674
Created attachment 412843 [details] Proposed patch (python 2.6)
Created attachment 412844 [details] Proposed patch (python 2.4)
Assigning CVE-2010-1634 here and setting priority to low. As noted in the upstream bug, ulaw2lin, alaw2lin and adpcm2lin integer overflows do not lead to buffer overflows. lin2lin integer overflow can result in buffer overflow - audioop.lin2lin("A"*0x40000001, 1, 4). ratecv requires special nchannels argument value rather than special / oversize input. Upstream patches: http://svn.python.org/view?rev=81045&view=rev http://svn.python.org/view?rev=81079&view=rev Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
python-2.6.2-8.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/python-2.6.2-8.fc12
python-2.6.4-27.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/python-2.6.4-27.fc13
python-2.6-14.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/python-2.6-14.fc11
python3-3.1.2-6.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/python3-3.1.2-6.fc13
python26-2.6.5-5.el5 has been submitted as an update for Fedora EPEL 5. http://admin.fedoraproject.org/updates/python26-2.6.5-5.el5
python-2.6.4-27.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
python-2.6.2-8.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2011:0027 https://rhn.redhat.com/errata/RHSA-2011-0027.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Via RHSA-2011:0491 https://rhn.redhat.com/errata/RHSA-2011-0491.html
Statement: (none)