LWN.net Logo

python: information leak

Package(s):python CVE #(s):CVE-2011-1521
Created:May 3, 2011 Updated:October 18, 2012
Description: From the Pardus advisory:

A security flaw was found in the way handlers for ftp:// and file:// URL schemes in the Python urllib and urllib2 extensible libraries processed the urllib open URL request. A remote attacker could use this flaw to access sensitive information or cause a denial of service (excessive CPU and memory use) of a Python web application, processing URLs, via a specially- crafted urllib open URL request.

Alerts:
Ubuntu USN-1314-1 2011-12-19
SUSE SUSE-SR:2011:010 2011-05-31
CentOS CESA-2011:0491 2011-05-05
CentOS CESA-2011:0492 2011-05-05
Red Hat RHSA-2011:0491-01 2011-05-05
Pardus 2011-70 2011-05-02
Red Hat RHSA-2011:0554-01 2011-05-19
SUSE SUSE-SR:2011:009 2011-05-17
openSUSE openSUSE-SU-2011:0484-1 2011-05-13
Red Hat RHSA-2011:0492-01 2011-05-05
Mandriva MDVSA-2011:096 2011-05-22
Ubuntu USN-1592-1 2012-10-02
Ubuntu USN-1596-1 2012-10-04
Ubuntu USN-1613-2 2012-10-17
Ubuntu USN-1613-1 2012-10-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds