[El-errata] ELSA-2009-1176 Moderate: Enterprise Linux 5 python security update

Errata Announcements for Enterprise Linux el-errata at oss.oracle.com
Mon Jul 27 11:20:36 PDT 2009


Enterprise Linux Security Advisory ELSA-2009-1176

https://rhn.redhat.com/errata/RHSA-2009-1176.html

The following updated rpms for Enterprise Linux 5 have been uploaded to 
the Unbreakable Linux Network:

i386:
python-2.4.3-24.el5_3.6.i386.rpm
python-devel-2.4.3-24.el5_3.6.i386.rpm
python-tools-2.4.3-24.el5_3.6.i386.rpm
tkinter-2.4.3-24.el5_3.6.i386.rpm

x86_64:
python-2.4.3-24.el5_3.6.x86_64.rpm
python-devel-2.4.3-24.el5_3.6.i386.rpm
python-devel-2.4.3-24.el5_3.6.x86_64.rpm
python-tools-2.4.3-24.el5_3.6.x86_64.rpm
tkinter-2.4.3-24.el5_3.6.x86_64.rpm

SRPMS:
http://oss.oracle.com/el5/SRPMS-updates/python-2.4.3-24.el5_3.6.src.rpm

Description of changes:

[2.4.3-24.el5_3.6]
- Fix all of the low priority security bugs:
- Resolves: rhbz#486351
- Multiple integer overflows in python core (CVE-2008-2315)
- Resolves: 455008
- PyString_FromStringAndSize does not check for negative size values 
(CVE-2008-1887)
- Resolves: 443810
- Multiple integer overflows discovered by Google (CVE-2008-3143)
- Resolves: 455013
- Multiple buffer overflows in unicode processing (CVE-2008-3142)
- Resolves: 454990
- Potential integer underflow and overflow in the PyOS_vsnprintf C API 
function (CVE-2008-3144)
- Resolves: 455018
- imageop module multiple integer overflows (CVE-2008-4864)
- Resolves: 469656
- stringobject, unicodeobject integer overflows (CVE-2008-5031)
- Resolves: 470915
- integer signedness error in the zlib extension module (CVE-2008-1721)
- Resolves: 442005
- off-by-one locale.strxfrm() (possible memory disclosure) (CVE-2007-2052)
- Resolves: 235093
- imageop module heap corruption (CVE-2007-4965)
- Resolves: 295971





More information about the El-errata mailing list