LWN.net Logo

Mageia alert MGASA-2012-0170 (python)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2012-0170: python-2.7.3-2.2.mga2 (2/core)
Date:  Thu, 19 Jul 2012 01:40:27 +0200
Message-ID:  <20120718234027.GA2730@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2012-0170 Date: July 19th, 2012 Affected releases: 2 Description: Updated python packages fix security vulnerabilities: A race condition was found in the way the Python distutils module set file permissions during the creation of the .pypirc file. If a local user had access to the home directory of another user who is running distutils, they could use this flaw to gain access to that user's .pypirc file, which can contain usernames and passwords for code repositories (CVE-2011-4944). Additionally, python has been built against the system expat and ffi libraries, to avoid any future issues with those. Updated Packages: python-2.7.3-2.2.mga2 python-docs-2.7.3-2.2.mga2 tkinter-2.7.3-2.2.mga2 tkinter-apps-2.7.3-2.2.mga2 lib(64)python2.7-2.7.3-2.2.mga2 lib(64)python-devel-2.7.3-2.2.mga2 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4944 http://lists.opensuse.org/opensuse-updates/2012-05/msg000... http://www.mandriva.com/en/support/security/advisories/?d... https://bugs.mageia.org/show_bug.cgi?id=5843 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds