CVE-2016-5636: Python
Critical severity, CVSS 9.8. EPSS: 25.5% chance of exploitation in the next 30 days.
Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer overflow.
Affected products
- Python Python: version 3.0 only; version 3.0.1 only; version 3.1.0 only; version 3.1.1 only; version 3.1.2 only; version 3.1.3 only; …
Published 2016-09-02. Last modified 2026-06-17.