Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Ubuntu 13.04 on me high-end box - Horrible
· NVIDIA GeForce Chips Comparison Table and more
· CSF 6.09 released
· Microsoft and Google agree to build YouTube app for Windows Phone 8
· OS X 10.8.4 Build 12E55 Seeded to Developers
· Wine 1.5.31 released
· Libxvmc/Libx11 Updates for Debian
· OCZ Vertex 450 SSD Reviews and more
· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?

Upcoming News
· Appointee to the Fedora Board; election nominations closing imminently.
· Logitech k310 Washable Keyboard
· [Tech ARP] BIOS Option Of The Week - Hardware Prefetcher
· SuperTooth HD VOICE Bluetooth Speakerphone Review @ TestFreaks
· A Futurelooks News Flash - An Affordable Titan – N?= VIDIA’s GEFORCE GTX 780 Reviewed
· News: AMD's A4-5000 'Kabini' APU reviewed
· Wine release 1.5.31
· NVIDIA GeForce Chips Comparison Table @ Hardware Secrets
· Resident Evil Revelations Video Review with Kaeyi Dream @ HardwareHeaven.com
· [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: update to version 21.0

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6522 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 723 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4611 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 799 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1179 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » March 2007 » USN-430-1: mod_python vulnerability

USN-430-1: mod_python vulnerability

Posted by Bob on: 03/06/2007 11:15 PM [ Print | 0 comment(s) ]

A new mod_python vulnerability update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-430-1 March 06, 2007
libapache2-mod-python vulnerability
CVE-2004-2680
==========================
==========================
=========

A security issue affects the following Ubuntu releases:

Ubuntu 5.10
Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 5.10:
libapache2-mod-python 3.1.3-3ubuntu1.1

Ubuntu 6.06 LTS:
libapache2-mod-python 3.1.4-0ubuntu1.1

After a standard system upgrade you need to restart Apache to effect the
necessary changes.

Details follow:

Miles Egan discovered that mod_python, when used in output filter mode,
did not handle output larger than 16384 bytes, and would display freed
memory, possibly disclosing private data. Thanks to Jim Garrison of the
Software Freedom Law Center for identifying the original bug as a
security vulnerability.


Updated packages for Ubuntu 5.10:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.3-3ubuntu1.1.diff.gz
Size/MD5: 42855 1529fea7b05b869a360b6bc68d52386e
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.3-3ubuntu1.1.dsc
Size/MD5: 810 63072c8e787515557969a57119e5d4c5
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.3.orig.tar.gz
Size/MD5: 293548 2e1983e35edd428f308b0dfeb1c23bfe

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python-doc_3.1.3-3ubuntu1.1_all.deb
Size/MD5: 101052 02819855dfc2346b9582b8687b7ce3f3
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.3-3ubuntu1.1_all.deb
Size/MD5: 12890 29d8f3ad95844a81ef2bac9921be4ea2

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/universe/liba/libapache2-mod-pyt=
hon/libapache2-mod-python2.3_3.1.3-3ubuntu1.1_amd64.deb
Size/MD5: 88482 bbbc44abd50a165ae5df51d97c8b59f4
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.3-3ubuntu1.1_amd64.deb
Size/MD5: 88506 33430412a637252533673023a0eb556e

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/universe/liba/libapache2-mod-pyt=
hon/libapache2-mod-python2.3_3.1.3-3ubuntu1.1_i386.deb
Size/MD5: 80692 43cf25dacf95697200b50280ff4b1c74
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.3-3ubuntu1.1_i386.deb
Size/MD5: 80722 7003abb20896ed3d218febd92ad176c2

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/universe/liba/libapache2-mod-pyt=
hon/libapache2-mod-python2.3_3.1.3-3ubuntu1.1_powerpc.deb
Size/MD5: 85980 75be899b0568d8a332ac04ae820d955e
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.3-3ubuntu1.1_powerpc.deb
Size/MD5: 86010 f706350855b692417a9d32f2c1962abd

sparc architecture (Sun SPARC/UltraSPARC)

http://security.ubuntu.com/ubuntu/pool/universe/liba/libapache2-mod-pyt=
hon/libapache2-mod-python2.3_3.1.3-3ubuntu1.1_sparc.deb
Size/MD5: 82038 0b8d6e081d3e6506139a9fac4674d8ad
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.3-3ubuntu1.1_sparc.deb
Size/MD5: 82078 71b5c528867eb166cd140a564d3fde0b

Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.4-0ubuntu1.1.diff.gz
Size/MD5: 25348 f53b1e046220df8e1cdcf4cd602ac563
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.4-0ubuntu1.1.dsc
Size/MD5: 769 41f6be106885d14e487317c57cc8e940
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.4.orig.tar.gz
Size/MD5: 308510 607175958137b06bcda91110414c82a1

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python-doc_3.1.4-0ubuntu1.1_all.deb
Size/MD5: 113106 0b66fc0e0a15cbc6a57df85100e3ca62
http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python_3.1.4-0ubuntu1.1_all.deb
Size/MD5: 13076 5488f0a55a436648c587e9a300d63881

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.4-0ubuntu1.1_amd64.deb
Size/MD5: 88678 8542060889c4b3c32a6937070911bf33

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.4-0ubuntu1.1_i386.deb
Size/MD5: 80676 13f3b9e1d7260ad8c34f7597954ed315

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.4-0ubuntu1.1_powerpc.deb
Size/MD5: 85840 684789cb3c7acbeed9064200554d8da4

sparc architecture (Sun SPARC/UltraSPARC)

http://security.ubuntu.com/ubuntu/pool/main/liba/libapache2-mod-python/=
libapache2-mod-python2.4_3.1.4-0ubuntu1.1_sparc.deb
Size/MD5: 82000 297ab56501345f12ee9c6c0951287980


--E13BgyNx05feLLmH
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF7eWuH/9LqRcGPm0RAl2fAJ9MvKBfPngLfQoveZnuYvXQNyJNiACgjg9S
0ccxIpvMTY8DGz0Nd5T9iC0=
=h5MZ
-----END PGP SIGNATURE-----


Bookmark and Share

« electric sheep 2.6.7b3 Beta · USN-429-1: tcpdump vulnerability »

Linux Compatible » News » March 2007 » USN-430-1: mod_python vulnerability
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition