Date:         Tue, 11 Dec 2007 15:38:26 -0600
Reply-To:     Troy Dawson 
Sender:       Security Errata for Scientific Linux
              
From:         Troy Dawson 
Subject:      Security ERRATA for python on SL4.x, SL3.x i386/x86_64
Comments: To: "scientific-linux-errata@fnal.gov"
          

Synopsis:	Moderate: python security update
Issue date:	2007-12-10
CVE Names:	CVE-2006-7228 CVE-2007-2052 CVE-2007-4965

An integer overflow flaw was discovered in the way Python's pcre module
handled certain regular expressions. If a Python application used the pcre
module to compile and execute untrusted regular expressions, it may be
possible to cause the application to crash, or allow arbitrary code
execution with the privileges of the Python interpreter. (CVE-2006-7228)

A flaw was discovered in the strxfrm() function of Python's locale module.
Strings generated by this function were not properly NULL-terminated. This
may possibly cause disclosure of data stored in the memory of a Python
application using this function. (CVE-2007-2052)

Multiple integer overflow flaws were discovered in Python's imageop module.
If an application written in Python used the imageop module to process
untrusted images, it could cause the application to crash, enter an
infinite loop, or possibly execute arbitrary code with the privileges of
the Python interpreter. (CVE-2007-4965)

SL 3.0.x

    SRPMS:
python-2.2.3-6.8.src.rpm
    i386:
python-2.2.3-6.8.i386.rpm
python-devel-2.2.3-6.8.i386.rpm
python-docs-2.2.3-6.8.i386.rpm
python-tools-2.2.3-6.8.i386.rpm
tkinter-2.2.3-6.8.i386.rpm
    x86_64:
python-2.2.3-6.8.x86_64.rpm
python-devel-2.2.3-6.8.x86_64.rpm
python-docs-2.2.3-6.8.x86_64.rpm
python-tools-2.2.3-6.8.x86_64.rpm
tkinter-2.2.3-6.8.x86_64.rpm

SL 4.x

    SRPMS:
python-2.3.4-14.4.el4_6.1.src.rpm
    i386:
python-2.3.4-14.4.el4_6.1.i386.rpm
python-devel-2.3.4-14.4.el4_6.1.i386.rpm
python-docs-2.3.4-14.4.el4_6.1.i386.rpm
python-tools-2.3.4-14.4.el4_6.1.i386.rpm
tkinter-2.3.4-14.4.el4_6.1.i386.rpm
    x86_64:
python-2.3.4-14.4.el4.1.x86_64.rpm
python-devel-2.3.4-14.4.el4.1.x86_64.rpm
python-docs-2.3.4-14.4.el4.1.x86_64.rpm
python-tools-2.3.4-14.4.el4.1.x86_64.rpm
tkinter-2.3.4-14.4.el4.1.x86_64.rpm

-Connie Sieh
-Troy Dawson

SciLinux: CVE-2006-7228 python SL4.x, SL3.x i386/x86_64

Moderate: python security update

Summary

Date:         Tue, 11 Dec 2007 15:38:26 -0600Reply-To:     Troy Dawson Sender:       Security Errata for Scientific Linux              From:         Troy Dawson Subject:      Security ERRATA for python on SL4.x, SL3.x i386/x86_64Comments: To: "scientific-linux-errata@fnal.gov"          Synopsis:	Moderate: python security updateIssue date:	2007-12-10CVE Names:	CVE-2006-7228 CVE-2007-2052 CVE-2007-4965An integer overflow flaw was discovered in the way Python's pcre modulehandled certain regular expressions. If a Python application used the pcremodule to compile and execute untrusted regular expressions, it may bepossible to cause the application to crash, or allow arbitrary codeexecution with the privileges of the Python interpreter. (CVE-2006-7228)A flaw was discovered in the strxfrm() function of Python's locale module.Strings generated by this function were not properly NULL-terminated. Thismay possibly cause disclosure of data stored in the memory of a Pythonapplication using this function. (CVE-2007-2052)Multiple integer overflow flaws were discovered in Python's imageop module.If an application written in Python used the imageop module to processuntrusted images, it could cause the application to crash, enter aninfinite loop, or possibly execute arbitrary code with the privileges ofthe Python interpreter. (CVE-2007-4965)SL 3.0.x    SRPMS:python-2.2.3-6.8.src.rpm    i386:python-2.2.3-6.8.i386.rpmpython-devel-2.2.3-6.8.i386.rpmpython-docs-2.2.3-6.8.i386.rpmpython-tools-2.2.3-6.8.i386.rpmtkinter-2.2.3-6.8.i386.rpm    x86_64:python-2.2.3-6.8.x86_64.rpmpython-devel-2.2.3-6.8.x86_64.rpmpython-docs-2.2.3-6.8.x86_64.rpmpython-tools-2.2.3-6.8.x86_64.rpmtkinter-2.2.3-6.8.x86_64.rpmSL 4.x    SRPMS:python-2.3.4-14.4.el4_6.1.src.rpm    i386:python-2.3.4-14.4.el4_6.1.i386.rpmpython-devel-2.3.4-14.4.el4_6.1.i386.rpmpython-docs-2.3.4-14.4.el4_6.1.i386.rpmpython-tools-2.3.4-14.4.el4_6.1.i386.rpmtkinter-2.3.4-14.4.el4_6.1.i386.rpm    x86_64:python-2.3.4-14.4.el4.1.x86_64.rpmpython-devel-2.3.4-14.4.el4.1.x86_64.rpmpython-docs-2.3.4-14.4.el4.1.x86_64.rpmpython-tools-2.3.4-14.4.el4.1.x86_64.rpmtkinter-2.3.4-14.4.el4.1.x86_64.rpm-Connie Sieh-Troy Dawson



Security Fixes

Severity

Related News