You are here
Home > Preporuke > Ranjivost programskog paketa python3

Ranjivost programskog paketa python3

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-2418
2014-02-12 14:04:31
——————————————————————————–

Name : python3
Product : Fedora 20
Version : 3.3.2
Release : 9.fc20
URL : http://www.python.org/
Summary : Version 3 of the Python programming language aka Python 3000
Description :
Python 3 is a new version of the language that is incompatible with the 2.x
line of releases. The language is mostly the same, but many details, especially
how built-in objects like dictionaries and strings work, have changed
considerably, and a lot of deprecated features have finally been removed.

——————————————————————————–
Update Information:

Buffer overflow fix.

See upstream issue: http://bugs.python.org/issue20246
——————————————————————————–
ChangeLog:

* Mon Feb 10 2014 Tomas Radej <tradej@redhat.com> – 3.3.2-9
– Fixed buffer overflow (upstream patch)
Resolves: rhbz#1062374
——————————————————————————–
References:

[ 1 ] Bug #1062370 – CVE-2014-1912 python: buffer overflow in socket.recvfrom_into()
https://bugzilla.redhat.com/show_bug.cgi?id=1062370
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update python3’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2014-02-0005-ADV
CveCVE-2014-1912
ID izvornikaFEDORA-2014-2418
Proizvodpython3
Izvorhttp://www.redhat.com
Top
More in Preporuke
Sigurnosni propust programskog paketa numpy

Otkriven je sigurnosni propust programskog paketa numpy koji je mogao biti iskorišten za mijenjanje proizvoljnih datoteka dostupnih korisniku koji pokreće...

Close