|
|
Subscribe / Log in / New account

Mageia alert MGASA-2013-0330 (python-scipy)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2013-0330: Updated python-scipy packages fix a security vulnerability and missing deps
Date:  Wed, 20 Nov 2013 21:22:32 +0100
Message-ID:  <20131120202232.CF08148C62@valstar.mageia.org>

MGASA-2013-0330 - Updated python-scipy packages fix a security vulnerability and missing deps Publication date: 20 Nov 2013 URL: http://advisories.mageia.org/MGASA-2013-0330.html Type: security Affected Mageia releases: 2, 3 CVE: CVE-2013-4251 Description: Updated python-scipy package fixes security vulnerability: scipy.weave will use /tmp/[username] as persistent storage (cache), but it does not check whether or not this directory already exists, does not check whether it is a directory or a symlink, and also does not verify permissions or ownership, which could allow someone to place code in this directory that would be executed as the user running scipy.weave (CVE-2013-4251). The update also adds some missing dependencies. References: - https://lists.fedoraproject.org/pipermail/package-announc... - https://bugs.mageia.org/show_bug.cgi?id=11555 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4251 SRPMS: - 3/core/python-scipy-0.9.0-7.3.mga3 - 2/core/python-scipy-0.9.0-3.4.mga2


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds