[El-errata] ELSA-2009-1178 Moderate: Enterprise Linux 3 python security update

Errata Announcements for Enterprise Linux el-errata at oss.oracle.com
Mon Jul 27 11:20:58 PDT 2009


Enterprise Linux Security Advisory ELSA-2009-1178

https://rhn.redhat.com/errata/RHSA-2009-1178.html

The following updated rpms for Enterprise Linux 3 have been uploaded to 
the Unbreakable Linux Network:

i386:
python-2.2.3-6.11.i386.rpm
python-devel-2.2.3-6.11.i386.rpm
python-tools-2.2.3-6.11.i386.rpm
tkinter-2.2.3-6.11.i386.rpm

x86_64:
python-2.2.3-6.11.x86_64.rpm
python-devel-2.2.3-6.11.x86_64.rpm
python-tools-2.2.3-6.11.x86_64.rpm
tkinter-2.2.3-6.11.x86_64.rpm

SRPMS:
http://oss.oracle.com/el3/SRPMS-updates/python-2.2.3-6.11.src.rpm

Description of changes:

[2.2.3-6.11]
- Fix all of the low priority security bugs:
- Resolves: rhbz#486114
- Multiple integer overflows in python core (CVE-2008-2315)
- Resolves: 455008
- PyString_FromStringAndSize does not check for negative size values 
(CVE-2008-1887)
- Resolves: 443810
- Multiple integer overflows discovered by Google (CVE-2008-3143)
- Resolves: 455013
- Multiple buffer overflows in unicode processing (CVE-2008-3142)
- Resolves: 454990
- Potential integer underflow and overflow in the PyOS_vsnprintf C API 
function (CVE-2008-3144)
- Resolves: 455018
- imageop module multiple integer overflows (CVE-2008-4864)
- Resolves: 469656
- stringobject, unicodeobject integer overflows (CVE-2008-5031)
- Resolves: 470915
- imageop module integer overflows (CVE-2008-1679)
- CVE-2008-1679 patch is part of python-2.2.3-CVE-2008-4864-imageop-1.patch
- Resolves: 441306





More information about the El-errata mailing list