[security - medium] python27 security, bug fix, and enhancement update

エラータID: AXSA:2017-1647:01

リリース日: 
2017/05/11 Thursday - 00:46
題名: 
[security - medium] python27 security, bug fix, and enhancement update
影響のあるチャネル: 
Asianux Server 4 for x86_64
Severity: 
Moderate
Description: 

python27-mod_wsgi
The mod_wsgi adapter is an Apache module that provides a WSGI compliant
interface for hosting Python based web applications within Apache. The
adapter is written completely in C code against the Apache C runtime and
for hosting WSGI applications within Apache has a lower overhead than using
existing WSGI adapters for mod_python or CGI.

python27-python
Python is an interpreted, interactive, object-oriented programming
language often compared to Tcl, Perl, Scheme or Java. Python includes
modules, classes, exceptions, very high level dynamic data types and
dynamic typing. Python supports interfaces to many system calls and
libraries, as well as to various windowing systems (X11, Motif, Tk,
Mac and MFC).

Programmers can write new built-in modules for Python in C or C .
Python can be used as an extension language for applications that need
a programmable interface.

Note that documentation for Python is provided in the python-docs
package.

This package provides the "python" executable; most of the actual
implementation is within the "python-libs" package.

python27-python-coverage
Coverage.py is a Python module that measures code coverage during Python
execution. It uses the code analysis tools and tracing hooks provided in the
Python standard library to determine which lines are executable, and which
have been executed.

python27-python-pip
Pip is a replacement for `easy_install
<http://peak.telecommunity.com/DevCenter/EasyInstall>`_. It uses mostly the
same techniques for finding packages, so packages that were made
easy_installable should be pip-installable as well.

python27-python-setuptools
Setuptools is a collection of enhancements to the Python distutils that allow
you to more easily build and distribute Python packages, especially ones that
have dependencies on other packages.

This package contains the runtime components of setuptools, necessary to
execute the software that requires pkg_resources.py.

This package contains the distribute fork of setuptools.

python27-python-virtualenv
virtualenv is a tool to create isolated Python environments. virtualenv
is a successor to workingenv, and an extension of virtual-python. It is
written by Ian Bicking, and sponsored by the Open Planning Project. It is
licensed under an MIT-style permissive license.

Security issues fixed with this release:

CVE-2014-9365
The HTTP clients in the (1) httplib, (2) urllib, (3) urllib2, and (4)
xmlrpclib libraries in CPython (aka Python) 2.x before 2.7.9 and 3.x
before 3.4.3, when accessing an HTTPS URL, do not (a) check the
certificate against a trust store or verify that the server hostname
matches a domain name in the subject's (b) Common Name or (c)
subjectAltName field of the X.509 certificate, which allows
man-in-the-middle attackers to spoof SSL servers via an arbitrary
valid certificate.

Security Fix(es) in the python27-python component:

解決策: 

Update package.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. python27-mod_wsgi-4.5.13-1.AXS4.src.rpm
    MD5: 09f92a53c92ac3e73f745acf2674f7cc
    SHA-256: a978c2e605fa9c1fe101cb71aad75602189c7aeee53c07680f1f088289209471
    Size: 1.75 MB
  2. python27-python-coverage-3.6-4.AXS4.src.rpm
    MD5: c8501aee15e729355d55189185c5c4e7
    SHA-256: f6876bd0585a175526795d2de33c570823d60480c91f15c5f00a7bae95db5dff
    Size: 233.70 kB
  3. python27-python-pip-8.1.2-2.AXS4.src.rpm
    MD5: 90238397c6db28170fa5300b8ac598f2
    SHA-256: 2ace3321a5d39d251e50621e254803207e0e9de6417239fe0e1d22271c715701
    Size: 1.09 MB
  4. python27-python-setuptools-0.9.8-4.AXS4.src.rpm
    MD5: 9d8efd69f814938359a538e38c165af9
    SHA-256: 81159bd7e23bcf2f72b2984171197b55f5ce7ddd03633568a254629aaef68659
    Size: 770.12 kB
  5. python27-python-2.7.13-3.0.1.AXS4.src.rpm
    MD5: 2dbbda08fefd8af3312ac9e683b7b3c4
    SHA-256: c7d55dc7907245c3df49f3107eec6e0e6087aa896d3801cfac4084ef03fb2379
    Size: 12.08 MB

Asianux Server 4 for x86_64
  1. python27-mod_wsgi-4.5.13-1.AXS4.x86_64.rpm
    MD5: c986e293c58f2ec4fbe928542ca511af
    SHA-256: 76caf03cd4d84bfc99bdc787fa82eaef40269043baa5511406d90aa093926f47
    Size: 94.80 kB
  2. python27-python-coverage-3.6-4.AXS4.x86_64.rpm
    MD5: 38a71f825e2e0a832838061b7b120b3c
    SHA-256: 0fb2348f8feaeda67928285be53b92b3bea0590b99c7ba575036e1d7343803af
    Size: 153.54 kB
  3. python27-python-pip-8.1.2-2.AXS4.noarch.rpm
    MD5: c03506fdbbee2c734470e77149a2e9ce
    SHA-256: daec80bf0e9c6f8b034cfaaffd7879323402385ab44050e541c81224d76ab14f
    Size: 1.69 MB
  4. python27-python-setuptools-0.9.8-4.AXS4.noarch.rpm
    MD5: 6d81ab5812c7371bcb96d58856537f24
    SHA-256: 30ff1846ca8394ff22f5fe7c9e57f79c77a7fdbe8cd66e7c629a1a7fbab132c1
    Size: 422.00 kB
  5. python27-python-2.7.13-3.0.1.AXS4.x86_64.rpm
    MD5: 500517fe0fe39352f6882962a4f32138
    SHA-256: 78cedff6cd53f5e4aeefcd0d8b9abee5d1dd72b8b4a78774242edd01850a90d3
    Size: 83.31 kB
  6. python27-python-debug-2.7.13-3.0.1.AXS4.x86_64.rpm
    MD5: a71ba2a995253bf4117a145d0694ad81
    SHA-256: d0e31850648c6eb6bde35a1e79c3c3d9e9329718862696b1dd2d04b5e87a8e5f
    Size: 1.90 MB
  7. python27-python-devel-2.7.13-3.0.1.AXS4.x86_64.rpm
    MD5: b3b53e2dd11bbe1010ec41dd494c0a19
    SHA-256: 054941e43b5f836c4f2cbe409077951a601bc4106c7dbe406355dbdaa94818be
    Size: 389.11 kB
  8. python27-python-libs-2.7.13-3.0.1.AXS4.x86_64.rpm
    MD5: c5ee3bb11791ebed949a3c0c0e3ee545
    SHA-256: 4b1924e0a07af40c33b3a8a27b29979019f14421d8588fc796875ff44ab6e225
    Size: 5.78 MB
  9. python27-python-test-2.7.13-3.0.1.AXS4.x86_64.rpm
    MD5: 1cfe15df4c4cd6a2e2e4933c6cecbdfc
    SHA-256: 5eee0a582e635021dd365e6308f5d337a924e92afcc5f6e6ca19d296bf16bead
    Size: 4.57 MB
  10. python27-python-tools-2.7.13-3.0.1.AXS4.x86_64.rpm
    MD5: 798a70ac1ba1e38cf5d805767b595fc0
    SHA-256: 0ab33fcc32ee7010bd13f394c17eb9882d141bd2397e1fe2acb1eaeffa8c4104
    Size: 440.32 kB
  11. python27-tkinter-2.7.13-3.0.1.AXS4.x86_64.rpm
    MD5: 3a39c5e1f3d55f5b762fa860858e8d1e
    SHA-256: 67e8065c5a23485c1438d6d683755424e9a37ec091c9b809b92a00c442310137
    Size: 395.33 kB