Mandriva Linux Security Advisory 2009-003 – Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer overflow. Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c. The updated Python packages have been patched to correct these issues.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/73717/MDVSA-2009-003.txt
Source: https://packetstormsecurity.com/files/73717/Mandriva-Linux-Security-Advisory-2009-003.html

