Kod programskog paketa Python uočeno je i otklonjeno više sigurnosnih ranjivosti. Napadač ih je mogao iskoristiti za zaobilaženje postavljenih sigurnosnih ograničenja, pregled osjetljivih informacija, napad uskraćivanjem usluga (DoS) te dobivanje većih ovlasti u sustavu.
Problemi sigurnosti se događaju uslijed pogrešnog postavljanja dozvola za datoteke u "distutils" modulu, neodgovarajućeg listanja direktorija u komponenti "SimpleHTTPServer", pogreške u "impleXMLRPCServer", itd.
Posljedica:
Zloćudni korisnik navedene ranjivosti može iskoristiti za otkrivanje osjetljivih podataka, DoS (eng. Denial of Service) napad, dobivanje većih privilegija u sustavu te zaobilaženje postavljenih ograničenja.
Rješenje:
Svim se korisnicima savjetuje nadogradnja na ispravljene inačice.
CentOS Errata and Security Advisory 2012:0744 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-0744.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
68b40bb24637e5151d56ff980b14ede5db07951b6325d9a54ead3498527e65fd
python-2.6.6-29.el6_2.2.i686.rpm
8bcda8f75bde9eae4b89b264a28be6596a5a0bbe74caa150c745e0c517f59533
python-devel-2.6.6-29.el6_2.2.i686.rpm
a97bcae9e9764c21665fd4b43f3ef67897b8aa336c997078b5b079df1a3f458b
python-libs-2.6.6-29.el6_2.2.i686.rpm
0d659305707e6e7eabbdbf14b06367a4c2220c7c8446469d02851d1d9291a25d
python-test-2.6.6-29.el6_2.2.i686.rpm
d45f3d643582177adf242981bf66c89a8bcdf048bd64cdfceed6248a5e07364a
python-tools-2.6.6-29.el6_2.2.i686.rpm
5f5c9798bf941d3061a159484a1816b29cef3928404eda6da69ceb661d6439d3
tkinter-2.6.6-29.el6_2.2.i686.rpm
x86_64:
68b40bb24637e5151d56ff980b14ede5db07951b6325d9a54ead3498527e65fd
python-2.6.6-29.el6_2.2.i686.rpm
9d5f64d06c7cc75c166f635bd8d0a842d999d5a1f46ba51eb57c2b4ce3ac09f1
python-2.6.6-29.el6_2.2.x86_64.rpm
8bcda8f75bde9eae4b89b264a28be6596a5a0bbe74caa150c745e0c517f59533
python-devel-2.6.6-29.el6_2.2.i686.rpm
cd2eeb31d0c9795045d7fb38abe545193393af71257d98e382ca2a3c5d314e51
python-devel-2.6.6-29.el6_2.2.x86_64.rpm
a97bcae9e9764c21665fd4b43f3ef67897b8aa336c997078b5b079df1a3f458b
python-libs-2.6.6-29.el6_2.2.i686.rpm
901dd463ec89fb78dfc7f67e23f3d045422fd2d5a83d4d2bfa0ec4ea4aa4f929
python-libs-2.6.6-29.el6_2.2.x86_64.rpm
de7ddc6b116cd5b88aabb4d6b00d2f41bc0f95aa247c6e21790f59e78c58464b
python-test-2.6.6-29.el6_2.2.x86_64.rpm
00a7b81b38b804b71667f45570c54c5910c4d53c08aeb8072d21d4a381c5f4ac
python-tools-2.6.6-29.el6_2.2.x86_64.rpm
98339b5d758e08f8e9b6753c403da3879250b2d474197727cb417263f902efdf
tkinter-2.6.6-29.el6_2.2.x86_64.rpm
Source:
e6e6fdbb082ebe1240c55739e9ba357a86fd37a59b757fa51faf174e18526c96
python-2.6.6-29.el6_2.2.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
CentOS Errata and Security Advisory 2012:0745 Moderate
Upstream details at : https://rhn.redhat.com/errata/RHSA-2012-0745.html
The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )
i386:
8732b6917bb703e83bcedba44db574bb5c08b6fdc6078b3cc85a2a2c8764ab1e
python-2.4.3-46.el5_8.2.i386.rpm
686cf6c90f524d21a9ab6726d92a665728be79e405b0436d68c4ee1e7adfbb8e
python-devel-2.4.3-46.el5_8.2.i386.rpm
5ac75df1c01468be5adb94dd75c1bc72ee899a2cf4f93a33b42bf90370bc9aca
python-libs-2.4.3-46.el5_8.2.i386.rpm
64ab9d7cd165684ee8bace4ad12b3f2b44cc008760d8fdfb3a504f2335e8a18a
python-tools-2.4.3-46.el5_8.2.i386.rpm
c36a78764e6624defd97452951b957ec8c85177e340baa52ea74dcca15912987
tkinter-2.4.3-46.el5_8.2.i386.rpm
x86_64:
75a516ec99cfb3bfbeb2ed6289b91aca405aee98225d68b7f4087445d1b734d5
python-2.4.3-46.el5_8.2.x86_64.rpm
686cf6c90f524d21a9ab6726d92a665728be79e405b0436d68c4ee1e7adfbb8e
python-devel-2.4.3-46.el5_8.2.i386.rpm
4566def644dc427f74e946a767e11d2bed86cc9150a2b38a7234ab11eb599e29
python-devel-2.4.3-46.el5_8.2.x86_64.rpm
a99ed59ad78084a5bbe6fbaf811a428618529df9cd391bfb5420b66a6d4b9752
python-libs-2.4.3-46.el5_8.2.x86_64.rpm
532ebf0691f63c3f835ed394928790b8aa2af6ad1227ae248a87736cf38ea443
python-tools-2.4.3-46.el5_8.2.x86_64.rpm
282c9c7a70c4bd1f9b9da1becc280784839852c464814fcd8c91e0606b23bab0
tkinter-2.4.3-46.el5_8.2.x86_64.rpm
Source:
c0a95526d16a245d9b0537d7ff7b09225c1709d892885ff3489b58dad4661280
python-2.4.3-46.el5_8.2.src.rpm
--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
_______________________________________________
CentOS-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
http://lists.centos.org/mailman/listinfo/centos-announce
Posljednje sigurnosne preporuke