First published: Mon Dec 10 2007(Updated: )
Python is an interpreted, interactive, object-oriented programming<br>language.<br>An integer overflow flaw was discovered in the way Python's pcre module<br>handled certain regular expressions. If a Python application used the pcre<br>module to compile and execute untrusted regular expressions, it may be<br>possible to cause the application to crash, or allow arbitrary code<br>execution with the privileges of the Python interpreter. (CVE-2006-7228)<br>A flaw was discovered in the strxfrm() function of Python's locale module.<br>Strings generated by this function were not properly NULL-terminated. This<br>may possibly cause disclosure of data stored in the memory of a Python<br>application using this function. (CVE-2007-2052)<br>Multiple integer overflow flaws were discovered in Python's imageop module.<br>If an application written in Python used the imageop module to process<br>untrusted images, it could cause the application to crash, enter an<br>infinite loop, or possibly execute arbitrary code with the privileges of<br>the Python interpreter. (CVE-2007-4965)<br>Users of Python are advised to upgrade to these updated packages, which<br>contain backported patches to resolve these issues.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/python | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/python | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/python-devel | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/python-docs | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/python-tools | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/tkinter | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/python-devel | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/python-docs | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/python-tools | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
redhat/tkinter | <2.3.4-14.4.el4_6.1 | 2.3.4-14.4.el4_6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.