You are here
Home > Preporuke > Sigurnosni propust programskog paketa python-pycurl

Sigurnosni propust programskog paketa python-pycurl

  • Detalji os-a: FED
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2015-0de8163795
2015-11-27 16:47:02.532814
——————————————————————————–

Name : python-pycurl
Product : Fedora 22
Version : 7.19.5.1
Release : 3.fc22
URL : http://pycurl.sourceforge.net/
Summary : A Python interface to libcurl
Description :
PycURL is a Python interface to libcurl. PycURL can be used to fetch
objects identified by a URL from a Python program, similar to the
urllib Python module. PycURL is mature, very fast, and supports a lot
of features.

——————————————————————————–
Update Information:

python-pycurl-7.19.5.1-4.fc23 – fix a use after free issue with unicode
FORM_BUFFERPTR (#1277488) python-pycurl-7.19.5.1-3.fc22 – fix a use after
free issue with unicode FORM_BUFFERPTR (#1277488)
——————————————————————————–
References:

[ 1 ] Bug #1277489 – python-pycurl: Use-after-free vulnerability in HTTPPOST when using FORM_BUFFERPTR with Unicode string [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1277489
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update python-pycurl’ at the command line.
For more information, refer to “Managing Software with yum”,
available at https://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorTomislav Protega
Cert idNCERT-REF-2015-11-0004-ADV
ID izvornikaFEDORA-2015
Proizvodpython-pycurl
Izvorhttp://www.redhat.com
Top
More in Preporuke
Sigrurnosni propust programskog paketa abrt

Otkriven je sigurnosni propust u programskom paketu abrt za RHEL 6. Propust je posljedica nesigurnog korištenja privremenih direktorija. Lokalni napadač...

Close