Debian: python2.2 buffer overflow and restore functionality fix

    Date 10 Oct 2004
    Posted By LinuxSecurity Advisories
    This security advisory corrects DSA 458-2 which caused a problem in the gethostbyaddr routine.
    Debian Security Advisory DSA 458-3                     This email address is being protected from spambots. You need JavaScript enabled to view it.                             Martin Schulze
    October 10th, 2004             
    Package        : python2.2
    Vulnerability  : buffer overflow
    Problem-Type   : remote
    Debian-specific: no
    CVE Ids        : CAN-2004-0150
    BugTraq ID     : 9836
    Debian Bug     : 248946 269548
    This security advisory corrects DSA 458-2 which caused a problem in
    the gethostbyaddr routine.
    The original advisory said:
       Sebastian Schmidt discovered a buffer overflow bug in Python's
       getaddrinfo function, which could allow an IPv6 address, supplied by a
       remote attacker via DNS, to overwrite memory on the stack.
       This bug only exists in python 2.2 and 2.2.1, and only when IPv6
       support is disabled.  The python2.2 package in Debian woody meets
       these conditions (the 'python' package does not).
    For the stable distribution (woody), this bug has been fixed in
    version 2.2.1-4.6.
    The testing and unstable distribution (sid) are not affected by this
    We recommend that you update your python2.2 packages.
    Upgrade Instructions
    wget url
            will fetch the file for you
    dpkg -i file.deb
            will install the referenced file.
    If you are using the apt-get package manager, use the line for
    sources.list as given below:
    apt-get update
            will update the internal database
    apt-get upgrade
            will install corrected packages
    You may use an automated update by adding the resources from the
    footer to the proper configuration.
    Debian GNU/Linux 3.0 alias woody
