Subject: | |
From: | |
Reply To: | |
Date: | Fri, 18 Feb 2011 11:47:36 -0600 |
Content-Type: | text/plain |
Parts/Attachments: |
|
|
Synopsis: Low: python security and bug fix update
Issue date: 2011-02-16
CVE Names: CVE-2009-4134 CVE-2010-1449 CVE-2010-1450
Multiple flaws were found in the Python rgbimg module. If an application
written in Python was using the rgbimg module and loaded a
specially-crafted SGI image file, it could cause the application to
crash or, possibly, execute arbitrary code with the privileges of the
user running the application. (CVE-2009-4134, CVE-2010-1449, CVE-2010-1450)
This update also fixes the following bugs:
* Python 2.3.4's time.strptime() function did not correctly handle the
"%W" week number format string. This update backports the _strptime
implementation from Python 2.3.6, fixing this issue. (BZ#436001)
* Python 2.3.4's socket.htons() function returned
partially-uninitialized data on IBM System z, generally leading to
incorrect results. (BZ#513341)
* Python 2.3.4's pwd.getpwuid() and grp.getgrgid() functions did not
support the full range of user and group IDs on 64-bit architectures,
leading to "OverflowError" exceptions for large input values. This
update adds support for the full range of user and group IDs on 64-bit
architectures. (BZ#497540)
SL 4.x
SRPMS:
python-2.3.4-14.9.el4.src.rpm
i386:
python-2.3.4-14.9.el4.i386.rpm
python-devel-2.3.4-14.9.el4.i386.rpm
python-docs-2.3.4-14.9.el4.i386.rpm
python-tools-2.3.4-14.9.el4.i386.rpm
tkinter-2.3.4-14.9.el4.i386.rpm
x86_64:
python-2.3.4-14.9.el4.x86_64.rpm
python-devel-2.3.4-14.9.el4.x86_64.rpm
python-docs-2.3.4-14.9.el4.x86_64.rpm
python-tools-2.3.4-14.9.el4.x86_64.rpm
tkinter-2.3.4-14.9.el4.x86_64.rpm
-Connie Sieh
-Troy Dawson
|
|
|