Version 3.2.7 of mod_python,
the Apache Python language extension, is out. See the
online documentation for information on this version.
(Log in to post comments)
mod_python 3.2.7 released
Posted Feb 21, 2006 18:53 UTC (Tue) by cook (subscriber, #4)
[Link]
This version of mod_python has a
security vulnerability.
"If you are using the recently released mod_python 3.2.7 please beware that a
security issue was discovered in the FileSession code.
You are vulnerable only if you are using mod_python 3.2.7 AND you are using
FileSession to keep sessions. FileSession is new in 3.2.7 and is not enabled by
default, therefore if you are using mod_python Session in its default
configuration you are not vulnerable."