python-2.6.6-20.AXS4

エラータID: AXSA:2011-587:02

リリース日: 
2011/12/28 Wednesday - 11:33
題名: 
python-2.6.6-20.AXS4
影響のあるチャネル: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
High
Description: 

Python is an interpreted, interactive, object-oriented programming language often compared to Tcl, Perl, Scheme or Java. Python includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems (X11, Motif, Tk, Mac and MFC).
Programmers can write new built-in modules for Python in C or C++. Python can be used as an extension language for applications that need a programmable interface. This package contains most of the standard Python modules, as well as modules for interfacing to the Tix widget set for Tk and RPM.
Note that documentation for Python is provided in the python-docs package.
Security issues fixed with this release:
CVE-2010-3493
Multiple race conditions in smtpd.py in the smtpd module in Python 2.6, 2.7, 3.1, and 3.2 alpha allow remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, or the getpeername function having an ENOTCONN error, a related issue to CVE-2010-3492.
CVE-2011-1015
The is_cgi method in CGIHTTPServer.py in the CGIHTTPServer module in Python 2.5, 2.6, and 3.0 allows remote attackers to read script source code via an HTTP GET request that lacks a / (slash) character at the beginning of the URI.
CVE-2011-1521
The urllib and urllib2 modules in Python 2.x before 2.7.2 and 3.x before 3.2.1 process Location headers that specify redirection to file: URLs, which makes it easier for remote attackers to obtain sensitive information or cause a denial of service (resource consumption) via a crafted URL, as demonstrated by the file:///etc/passwd and file:///dev/zero URLs.

解決策: 

Update packages.

追加情報: 

From Asianux Server 4 SP1.

ダウンロード: 

SRPMS
  1. python-2.6.6-20.AXS4.src.rpm
    MD5: b9eedeb8d272863e742927888d0a5922
    SHA-256: 4a5588567033efe6e6216017c6db3317243d75577ed89ce2cb3418419375937f
    Size: 10.66 MB

Asianux Server 4 for x86
  1. python-2.6.6-20.AXS4.i686.rpm
    MD5: 1a3fd80b921c997af672fbef5bc4cac9
    SHA-256: 9ccb5a83e02f6031306f6b669efeb9120d7aabb48aa6272d39b07f9536b91dc0
    Size: 4.78 MB
  2. python-devel-2.6.6-20.AXS4.i686.rpm
    MD5: 444381938b87f862190d94eb08df77c0
    SHA-256: 2c5ace0008fa23a58c278ad5b237ed802e751ee4824879985b10fe8b9b6c116a
    Size: 163.29 kB
  3. python-libs-2.6.6-20.AXS4.i686.rpm
    MD5: f663b3398c3cfc401ac2c32704d5ba96
    SHA-256: 16c0eb24ce5171ecd1817b20bf4d9547d665f15618183f027e127fb01fafb6e5
    Size: 602.71 kB
  4. tkinter-2.6.6-20.AXS4.i686.rpm
    MD5: fc7a1a4d0fe8d5d922fb0a05b2868a92
    SHA-256: d9161e8f179a2bfec2164aeb165f49110f2cf71176365b7076c5f1845e1333f4
    Size: 247.85 kB

Asianux Server 4 for x86_64
  1. python-2.6.6-20.AXS4.x86_64.rpm
    MD5: e61d983dca87212bac925c464b33d598
    SHA-256: 8aedff385afe5d5c2e93449ad15e11a97e7ba6b631ca5568261d348ca62bbc5f
    Size: 4.81 MB
  2. python-devel-2.6.6-20.AXS4.x86_64.rpm
    MD5: f95c7c9a2d8b776af2fa6c4500f97215
    SHA-256: 92e345b139ab3ded39c9f66463a620720174b6a055619cd3636bd959f074d659
    Size: 162.74 kB
  3. python-libs-2.6.6-20.AXS4.x86_64.rpm
    MD5: 81fb12b62fe7190da05e781b261b46f4
    SHA-256: 91d2008157320d498b8b55f7a2c0e9b8816282b39dc947f61b38cff0f1ee9d52
    Size: 617.71 kB
  4. tkinter-2.6.6-20.AXS4.x86_64.rpm
    MD5: 61ff7aba15468bf9113152b01569ac5b
    SHA-256: 48e160165eccf0ae4676bff4e5073b5ad116bc7ae38b8af74569df50bef24ad5
    Size: 248.49 kB