Ubuntu 1616-1: Python 3.1 vulnerabilities

    Date24 Oct 2012
    CategoryUbuntu
    38
    Posted ByLinuxSecurity Advisories
    Several security issues were fixed in Python 3.1.
    
    ==========================================================================
    Ubuntu Security Notice USN-1616-1
    October 24, 2012
    
    python3.1 vulnerabilities
    ==========================================================================
    
    A security issue affects these releases of Ubuntu and its derivatives:
    
    - Ubuntu 11.04
    - Ubuntu 10.04 LTS
    
    Summary:
    
    Several security issues were fixed in Python 3.1.
    
    Software Description:
    - python3.1: An interactive high-level object-oriented language (version
    3.1)
    
    Details:
    
    It was discovered that Python would prepend an empty string to sys.path
    under certain circumstances. A local attacker with write access to the
    current working directory could exploit this to execute arbitrary code.
    This issue only affected Ubuntu 10.04 LTS. (CVE-2008-5983)
    
    It was discovered that the audioop module did not correctly perform input
    validation. If a user or automatated system were tricked into opening a
    crafted audio file, an attacker could cause a denial of service via
    application crash. These issues only affected Ubuntu 10.04 LTS.
    (CVE-2010-1634, CVE-2010-2089)
    
    It was discovered that Python distutils contained a race condition when
    creating the ~/.pypirc file. A local attacker could exploit this to obtain
    sensitive information. (CVE-2011-4944)
    
    It was discovered that SimpleXMLRPCServer did not properly validate its
    input when handling HTTP POST requests. A remote attacker could exploit
    this to cause a denial of service via excessive CPU utilization.
    (CVE-2012-0845)
    
    It was discovered that Python was susceptible to hash algorithm attacks.
    An attacker could cause a denial of service under certian circumstances.
    This update adds the '-R' command line option and honors setting the
    PYTHONHASHSEED environment variable to 'random' to salt str and datetime
    objects with an unpredictable value. (CVE-2012-1150)
    
    Serhiy Storchaka discovered that the UTF16 decoder in Python did not
    properly reset internal variables after error handling. An attacker could
    exploit this to cause a denial of service via memory corruption.
    (CVE-2012-2135)
    
    Update instructions:
    
    The problem can be corrected by updating your system to the following
    package versions:
    
    Ubuntu 11.04:
      python3.1                       3.1.3-1ubuntu1.2
      python3.1-minimal               3.1.3-1ubuntu1.2
    
    Ubuntu 10.04 LTS:
      python3.1                       3.1.2-0ubuntu3.2
      python3.1-minimal               3.1.2-0ubuntu3.2
    
    In general, a standard system update will make all the necessary changes.
    
    References:
      http://www.ubuntu.com/usn/usn-1616-1
      CVE-2008-5983, CVE-2010-1634, CVE-2010-2089, CVE-2011-4944,
      CVE-2012-0845, CVE-2012-1150, CVE-2012-2135
    
    Package Information:
      https://launchpad.net/ubuntu/+source/python3.1/3.1.3-1ubuntu1.2
      https://launchpad.net/ubuntu/+source/python3.1/3.1.2-0ubuntu3.2
    
    
    
    
    
    You are not authorised to post comments.

    Comments powered by CComment

    LinuxSecurity Poll

    What do you think of the articles on LinuxSecurity?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/24-what-do-you-think-of-the-quality-of-the-articles-on-linuxsecurity?task=poll.vote&format=json
    24
    radio
    [{"id":"87","title":"Excellent, don't change a thing!","votes":"39","type":"x","order":"1","pct":50,"resources":[]},{"id":"88","title":"Should be more technical","votes":"11","type":"x","order":"2","pct":14.1,"resources":[]},{"id":"89","title":"Should include more HOWTOs","votes":"28","type":"x","order":"3","pct":35.9,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.