RHSA-2009:1176: Moderate: python security update
Python is an interpreted, interactive, object-oriented programminglanguage.When the assert() system call was disabled, an input sanitization flaw wasrevealed in the Python string object implementation that led to a bufferoverflow. The missing check for negative size values meant the Pythonmemory allocator could allocate less memory than expected. This couldresult in arbitrary code execution with the Python interpreter'sprivileges. (CVE-2008-1887)Multiple buffer and integer overflow flaws were found in the Python Unicodestring processing and in the Python Unicode and string objectimplementations. An attacker could use these flaws to cause a denial ofservice (Python application crash). (CVE-2008-3142, CVE-2008-5031)Multiple integer overflow flaws were found in the Python imageop module. Ifa Python application used the imageop module to process untrusted images,it could cause the application to disclose sensitive information, crash or,potentially, execute arbitrary code with the Python interpreter'sprivileges. (CVE-2007-4965, CVE-2008-4864)Multiple integer underflow and overflow flaws were found in the Pythonsnprintf() wrapper implementation. An attacker could use these flaws tocause a denial of service (memory corruption). (CVE-2008-3144)Multiple integer overflow flaws were found in various Python modules. Anattacker could use these flaws to cause a denial of service (Pythonapplication crash). (CVE-2008-2315, CVE-2008-3143)An integer signedness error, leading to a buffer overflow, was foundin the Python zlib extension module. If a Python application requestedthe negative byte count be flushed for a decompression stream, it couldcause the application to crash or, potentially, execute arbitrary codewith the Python interpreter's privileges. (CVE-2008-1721)A flaw was discovered in the strxfrm() function of the Python localemodule. Strings generated by this function were not properlyNULL-terminated, which could possibly cause disclosure of data stored inthe memory of a Python application using this function. (CVE-2007-2052)Red Hat would like to thank David Remahl of the Apple Product Security teamfor responsibly reporting the CVE-2008-2315 issue.All Python users should upgrade to these updated packages, which containbackported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2009:1176?
The severity of RHSA-2009:1176 is classified as moderate.
How do I fix RHSA-2009:1176?
To fix RHSA-2009:1176, upgrade to the packages version 2.4.3-24.el5_3.6 or later.
What software is affected by RHSA-2009:1176?
RHSA-2009:1176 affects the python, python-devel, python-tools, and tkinter packages.
What vulnerability does RHSA-2009:1176 address?
RHSA-2009:1176 addresses an input sanitization flaw in Python that may lead to a buffer overflow.
What platforms are impacted by RHSA-2009:1176?
RHSA-2009:1176 impacts Red Hat Enterprise Linux 5 for both i386 and x86_64 architectures.