Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian 2.7.3-6+deb7u3 Critical: Python Memory Overflow and TLS Issues

debian
Calendar Grey March 17, 2014
Debian Logo
Update to remediate several vulnerabilities in Python: CVE-2013-4238 and CVE-2014-1912 on Debian platforms.
Multiple security issues were discovered in Python: CVE-2013-4238

Summary

Multiple security issues were discovered in Python:

CVE-2013-4238

Ryan Sleevi that NULL charactors in the subject alternate names of
SSL cerficates were parsed incorrectly.

CVE-2014-1912

Ryan Smith-Roberts discovered a buffer overflow in the
socket.recvfrom_into() function.

For the stable distribution (wheezy), these problems have been fixed in
version 2.7.3-6+deb7u2.

For the unstable distribution (sid), these problems have been fixed in
version 2.7.6-7.

We recommend that you upgrade your python2.7 packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: python2.7
CVE ID: CVE-2013-4238 CVE-2014-1912

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here