The zlib extension module in Python version 2.5.2 contains a method for flushing decompression streams that takes an input parameter of how much data to flush. This parameter is a signed integer that is not verified for sanity and is thus potentially negative. When passed a negative value memory is misallocated and then the signed integer is converted to an unsigned integer resulting in buffer overflow.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65407/ioactive-zlib.txt
Source: https://packetstormsecurity.com/files/65407/ioactive-zlib.txt.html

