[El-errata] ELSA-2009-1176 Moderate: Enterprise Linux 5 python security update
Errata Announcements for Enterprise Linux
el-errata at oss.oracle.com
Mon Jul 27 11:20:36 PDT 2009
Enterprise Linux Security Advisory ELSA-2009-1176
https://rhn.redhat.com/errata/RHSA-2009-1176.html
The following updated rpms for Enterprise Linux 5 have been uploaded to
the Unbreakable Linux Network:
i386:
python-2.4.3-24.el5_3.6.i386.rpm
python-devel-2.4.3-24.el5_3.6.i386.rpm
python-tools-2.4.3-24.el5_3.6.i386.rpm
tkinter-2.4.3-24.el5_3.6.i386.rpm
x86_64:
python-2.4.3-24.el5_3.6.x86_64.rpm
python-devel-2.4.3-24.el5_3.6.i386.rpm
python-devel-2.4.3-24.el5_3.6.x86_64.rpm
python-tools-2.4.3-24.el5_3.6.x86_64.rpm
tkinter-2.4.3-24.el5_3.6.x86_64.rpm
SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/python-2.4.3-24.el5_3.6.src.rpm
Description of changes:
[2.4.3-24.el5_3.6]
- Fix all of the low priority security bugs:
- Resolves: rhbz#486351
- Multiple integer overflows in python core (CVE-2008-2315)
- Resolves: 455008
- PyString_FromStringAndSize does not check for negative size values
(CVE-2008-1887)
- Resolves: 443810
- Multiple integer overflows discovered by Google (CVE-2008-3143)
- Resolves: 455013
- Multiple buffer overflows in unicode processing (CVE-2008-3142)
- Resolves: 454990
- Potential integer underflow and overflow in the PyOS_vsnprintf C API
function (CVE-2008-3144)
- Resolves: 455018
- imageop module multiple integer overflows (CVE-2008-4864)
- Resolves: 469656
- stringobject, unicodeobject integer overflows (CVE-2008-5031)
- Resolves: 470915
- integer signedness error in the zlib extension module (CVE-2008-1721)
- Resolves: 442005
- off-by-one locale.strxfrm() (possible memory disclosure) (CVE-2007-2052)
- Resolves: 235093
- imageop module heap corruption (CVE-2007-4965)
- Resolves: 295971
More information about the El-errata
mailing list