Critical severity9.8NVD Advisory· Published Nov 17, 2017· Updated May 13, 2026
CVE-2017-1000158
CVE-2017-1000158
Description
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
Affected products
4cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- bugs.python.org/issue30657nvdIssue TrackingPatchVendor Advisory
- www.securitytracker.com/id/1039890nvdThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2017/11/msg00035.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2017/11/msg00036.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/09/msg00030.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2018/09/msg00031.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/201805-02nvdThird Party Advisory
- www.debian.org/security/2018/dsa-4307nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20230216-0001/nvd
News mentions
0No linked articles in our index yet.