Chapter 1. Package Updates
210
Multiple buffer and integer overflow flaws were found in the Python Unicode string processing and in
the Python Unicode and string object implementations. An attacker could use these flaws to cause a
denial of service (Python application crash). (
CVE-2008-3142
1456
,
CVE-2008-5031
1457
)
Multiple integer overflow flaws were found in the Python imageop module. If a Python application used
the imageop module to process untrusted images, it could cause the application to disclose sensitive
information, crash or, potentially, execute arbitrary code with the Python interpreter's privileges.
(
CVE-2007-4965
1458
,
CVE-2008-4864
1459
)
Multiple integer underflow and overflow flaws were found in the Python snprintf() wrapper
implementation. An attacker could use these flaws to cause a denial of service (memory corruption).
(
CVE-2008-3144
1460
)
Multiple integer overflow flaws were found in various Python modules. An attacker could use
these flaws to cause a denial of service (Python application crash). (
CVE-2008-2315
1461
,
CVE-2008-3143
1462
)
An integer signedness error, leading to a buffer overflow, was found in the Python zlib extension
module. If a Python application requested the negative byte count be flushed for a decompression
stream, it could cause the application to crash or, potentially, execute arbitrary code with the Python
interpreter's privileges. (
CVE-2008-1721
1463
)
A flaw was discovered in the strxfrm() function of the Python locale module. Strings generated by this
function were not properly NULL-terminated, which could possibly cause disclosure of data stored in
the memory of a Python application using this function. (
CVE-2007-2052
1464
)
Red Hat would like to thank David Remahl of the Apple Product Security team for responsibly
reporting the CVE-2008-2315 issue.
All Python users should upgrade to these updated packages, which contain backported patches to
correct these issues.
1.183.2. RHBA-2009:1402: bug fix update
Updated python packages that fix several thread and subprocess bugs are now available for Red Hat
Enterprise Linux 5.
Python is an interpreted, interactive, object-oriented programming language often compared to Tcl,
Perl, Scheme or Java. Python includes modules, classes, exceptions, very high level dynamic data
types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to
various windowing systems (X11, Motif, Tk, Mac and MFC).
These updated packages apply fixes for the following bugs:
• processes were cleaned and their IDs recycled regardless of whether the processes had an active
reference. This meant that child processes had their IDs recycled before their parent called for a
1456
https://www.redhat.com/security/data/cve/CVE-2008-3142.html
1457
https://www.redhat.com/security/data/cve/CVE-2008-5031.html
1458
https://www.redhat.com/security/data/cve/CVE-2007-4965.html
1459
https://www.redhat.com/security/data/cve/CVE-2008-4864.html
1460
https://www.redhat.com/security/data/cve/CVE-2008-3144.html
1461
https://www.redhat.com/security/data/cve/CVE-2008-2315.html
1462
https://www.redhat.com/security/data/cve/CVE-2008-3143.html
1463
https://www.redhat.com/security/data/cve/CVE-2008-1721.html
1464
https://www.redhat.com/security/data/cve/CVE-2007-2052.html
Summary of Contents for ENTERPRISE 5.4 RELEASE NOTES
Page 1: ...Red Hat Enterprise Linux 5 4 Technical Notes Every Change to Every Package ...
Page 18: ...xviii ...
Page 306: ...288 ...
Page 464: ...446 ...
Page 466: ...448 ...