CVE-2017-1000158: Debian Linux

Critical severity, CVSS 9.8. EPSS: 7.9% chance of exploitation in the next 30 days.

CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)

Affected products

  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Python Python: before 2.7.15 (fixed in 2.7.15); from 3.4.0, before 3.4.8 (fixed in 3.4.8); from 3.5.0, before 3.5.5 (fixed in 3.5.5)

Published 2017-11-17. Last modified 2026-10-08.