LWN.net Logo

python: insecure file creation

Package(s):python CVE #(s):CVE-2011-4944
Created:May 30, 2012 Updated:October 18, 2012
Description: From the Novell bugzilla:

python distutils first creates ~/.pypirc and then calls chmod() to restrict permissions. This allows for a time window where the file is readable by others.

Alerts:
openSUSE openSUSE-SU-2012:0667-1 2012-05-30
Red Hat RHSA-2012:0744-01 2012-06-18
Red Hat RHSA-2012:0745-01 2012-06-18
CentOS CESA-2012:0745 2012-06-18
Scientific Linux SL-pyth-20120618 2012-06-18
Scientific Linux SL-pyth-20120618 2012-06-18
CentOS CESA-2012:0744 2012-06-18
Oracle ELSA-2012-0744 2012-06-19
Oracle ELSA-2012-0745 2012-06-19
Mandriva MDVSA-2012:097 2012-06-20
Mandriva MDVSA-2012:096 2012-06-20
Mandriva MDVSA-2012:096-1 2012-07-02
Mageia MGASA-2012-0169 2012-07-19
Mageia MGASA-2012-0170 2012-07-19
Ubuntu USN-1592-1 2012-10-02
Ubuntu USN-1596-1 2012-10-04
Ubuntu USN-1613-2 2012-10-17
Ubuntu USN-1613-1 2012-10-17
Ubuntu USN-1615-1 2012-10-23
Ubuntu USN-1616-1 2012-10-24
Mandriva MDVSA-2013:117 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds