CVE-2017-1000158: Debian Linux
Critical severity, CVSS 9.8. EPSS: 7.9% chance of exploitation in the next 30 days.
CPython (aka Python) up to 2.7.13 is vulnerable to an integer overflow in the PyString_DecodeEscape function in stringobject.c, resulting in heap-based buffer overflow (and possible arbitrary code execution)
Affected products
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Python Python: before 2.7.15 (fixed in 2.7.15); from 3.4.0, before 3.4.8 (fixed in 3.4.8); from 3.5.0, before 3.5.5 (fixed in 3.5.5)
Published 2017-11-17. Last modified 2026-10-08.