SCIENTIFIC-LINUX-ERRATA Archives

December 2007

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Tue, 11 Dec 2007 15:38:26 -0600
Content-Type:
text/plain
Parts/Attachments:
text/plain (58 lines)
Synopsis:	Moderate: python security update
Issue date:	2007-12-10
CVE Names:	CVE-2006-7228 CVE-2007-2052 CVE-2007-4965

An integer overflow flaw was discovered in the way Python's pcre module
handled certain regular expressions. If a Python application used the pcre
module to compile and execute untrusted regular expressions, it may be
possible to cause the application to crash, or allow arbitrary code
execution with the privileges of the Python interpreter. (CVE-2006-7228)

A flaw was discovered in the strxfrm() function of Python's locale module.
Strings generated by this function were not properly NULL-terminated. This
may possibly cause disclosure of data stored in the memory of a Python
application using this function. (CVE-2007-2052)

Multiple integer overflow flaws were discovered in Python's imageop module.
If an application written in Python used the imageop module to process
untrusted images, it could cause the application to crash, enter an
infinite loop, or possibly execute arbitrary code with the privileges of
the Python interpreter. (CVE-2007-4965)

SL 3.0.x

    SRPMS:
python-2.2.3-6.8.src.rpm
    i386:
python-2.2.3-6.8.i386.rpm
python-devel-2.2.3-6.8.i386.rpm
python-docs-2.2.3-6.8.i386.rpm
python-tools-2.2.3-6.8.i386.rpm
tkinter-2.2.3-6.8.i386.rpm
    x86_64:
python-2.2.3-6.8.x86_64.rpm
python-devel-2.2.3-6.8.x86_64.rpm
python-docs-2.2.3-6.8.x86_64.rpm
python-tools-2.2.3-6.8.x86_64.rpm
tkinter-2.2.3-6.8.x86_64.rpm

SL 4.x

    SRPMS:
python-2.3.4-14.4.el4_6.1.src.rpm
    i386:
python-2.3.4-14.4.el4_6.1.i386.rpm
python-devel-2.3.4-14.4.el4_6.1.i386.rpm
python-docs-2.3.4-14.4.el4_6.1.i386.rpm
python-tools-2.3.4-14.4.el4_6.1.i386.rpm
tkinter-2.3.4-14.4.el4_6.1.i386.rpm
    x86_64:
python-2.3.4-14.4.el4.1.x86_64.rpm
python-devel-2.3.4-14.4.el4.1.x86_64.rpm
python-docs-2.3.4-14.4.el4.1.x86_64.rpm
python-tools-2.3.4-14.4.el4.1.x86_64.rpm
tkinter-2.3.4-14.4.el4.1.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2