← All CVEs

CVE-2016-5636

critical · 9.8

Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.

9.8
CVSS
22.4%
EPSS (exploit prob.)
98th
EPSS percentile
2016-09-02
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
pythonpython3.0
pythonpython3.0.1
pythonpython3.1.0
pythonpython3.1.1
pythonpython3.1.2
pythonpython3.1.3
pythonpython3.1.4
pythonpython3.1.5
pythonpython3.2.0
pythonpython3.2.1
pythonpython3.2.2
pythonpython3.2.3
pythonpython3.2.4
pythonpython3.2.5
pythonpython3.2.6
pythonpython3.3.0
pythonpython3.3.1
pythonpython3.3.2
pythonpython3.3.3
pythonpython3.3.4
pythonpython3.3.5
pythonpython3.3.6
pythonpython3.4.0
pythonpython3.4.1
pythonpython3.4.2
pythonpython3.4.3
pythonpython3.4.4
pythonpython<= 2.7.11
pythonpython3.5.0
pythonpython3.5.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-5636