← Back

CVE-2016-5636

nvd nist
Published: Sep 2, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.

Affected (30)

Products: Python: Python
1 product
Python
Configuration A
27 vulnerable
Vulnerable SoftwareAffected Versions
Python
Version 3.0.1
Version 3.0
Version 3.1.0
Version 3.1.1
Version 3.1.2
Version 3.1.3
Version 3.1.4
Version 3.1.5
Version 3.2.0
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.3.0
Version 3.3.1
Version 3.3.2
Version 3.3.3
Version 3.3.4
Version 3.3.5
Version 3.3.6
Version 3.4.0
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 3.4.4
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.7.11
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Python
Version 3.5.0
Version 3.5.1

References (30)

Source: cve@mitre.org
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatch
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.