SciLinux: CVE-2006-7228 python SL4.x, SL3.x i386/x86_64
Summary
Date: Tue, 11 Dec 2007 15:38:26 -0600Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for python on SL4.x, SL3.x i386/x86_64Comments: To: "scientific-linux-errata@fnal.gov" Synopsis: Moderate: python security updateIssue date: 2007-12-10CVE Names: CVE-2006-7228 CVE-2007-2052 CVE-2007-4965An integer overflow flaw was discovered in the way Python's pcre modulehandled certain regular expressions. If a Python application used the pcremodule to compile and execute untrusted regular expressions, it may bepossible to cause the application to crash, or allow arbitrary codeexecution with the privileges of the Python interpreter. (CVE-2006-7228)A flaw was discovered in the strxfrm() function of Python's locale module.Strings generated by this function were not properly NULL-terminated. Thismay possibly cause disclosure of data stored in the memory of a Pythonapplication using this function. (CVE-2007-2052)Multiple integer overflow flaws were discovered in Python's imageop module.If an application written in Python used the imageop module to processuntrusted images, it could cause the application to crash, enter aninfinite loop, or possibly execute arbitrary code with the privileges ofthe Python interpreter. (CVE-2007-4965)SL 3.0.x SRPMS:python-2.2.3-6.8.src.rpm i386:python-2.2.3-6.8.i386.rpmpython-devel-2.2.3-6.8.i386.rpmpython-docs-2.2.3-6.8.i386.rpmpython-tools-2.2.3-6.8.i386.rpmtkinter-2.2.3-6.8.i386.rpm x86_64:python-2.2.3-6.8.x86_64.rpmpython-devel-2.2.3-6.8.x86_64.rpmpython-docs-2.2.3-6.8.x86_64.rpmpython-tools-2.2.3-6.8.x86_64.rpmtkinter-2.2.3-6.8.x86_64.rpmSL 4.x SRPMS:python-2.3.4-14.4.el4_6.1.src.rpm i386:python-2.3.4-14.4.el4_6.1.i386.rpmpython-devel-2.3.4-14.4.el4_6.1.i386.rpmpython-docs-2.3.4-14.4.el4_6.1.i386.rpmpython-tools-2.3.4-14.4.el4_6.1.i386.rpmtkinter-2.3.4-14.4.el4_6.1.i386.rpm x86_64:python-2.3.4-14.4.el4.1.x86_64.rpmpython-devel-2.3.4-14.4.el4.1.x86_64.rpmpython-docs-2.3.4-14.4.el4.1.x86_64.rpmpython-tools-2.3.4-14.4.el4.1.x86_64.rpmtkinter-2.3.4-14.4.el4.1.x86_64.rpm-Connie Sieh-Troy Dawson