GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Jan 20, 2014 3:50 am Post subject: [ GLSA 201401-04 ] Python: Multiple vulnerabilities |
|
|
Gentoo Linux Security Advisory
Title: Python: Multiple vulnerabilities (GLSA 201401-04)
Severity: normal
Exploitable: remote
Date: January 06, 2014
Updated: July 07, 2014
Bug(s): #325593, #355927, #358663, #396329, #403437, #469988
ID: 201401-04
Synopsis
Multiple vulnerabilities have been found in Python, the worst of
which allow remote attackers to cause a Denial of Service condition.
Background
Python is an interpreted, interactive, object-oriented programming
language.
Affected Packages
Package: dev-lang/python
Vulnerable: < 3.3.2-r1
Unaffected: >= 3.2.5-r1 < 3.2.6
Unaffected: >= 2.6.8 < 2.6.9
Unaffected: >= 2.7.3-r1 < 2.7.4
Unaffected: >= 3.3.2-r1
Unaffected: >= 2.6.9 < 2.6.10
Unaffected: >= 2.7.4 < 2.7.5
Unaffected: >= 2.7.5 < 2.7.6
Unaffected: >= 2.7.6 < 2.7.7
Unaffected: >= 2.7.7 < 2.7.8
Unaffected: >= 2.7.8 < 2.7.9
Unaffected: >= 2.7.9 < 2.7.10
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Python. Please review
the CVE identifiers referenced below for details.
Impact
A remote attacker could possibly cause a Denial of Service condition or
perform a man-in-the-middle attack to disclose sensitive information.
Workaround
There is no known workaround at this time.
Resolution
All Python 3.3 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/python-3.3.2-r1"
| All Python 3.2 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/python-3.2.5-r1"
| All Python 2.6 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/python-2.6.8"
| All Python 2.7 users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/python-2.7.3-r1"
|
References
CVE-2010-1634
CVE-2010-2089
CVE-2010-3492
CVE-2010-3493
CVE-2011-1015
CVE-2012-0845
CVE-2012-1150
CVE-2013-2099
Last edited by GLSA on Tue Jul 08, 2014 4:31 am; edited 1 time in total |
|