Mandriva Linux Security Advisory 2012-096-1

newsbot

newsbot

RSS Feed
Mandriva Linux Security Advisory 2012-096 - Multiple vulnerabilities has been discovered and corrected in python. The _ssl module would always disable the CBC IV attack countermeasure. A flaw was found in the way the Python SimpleHTTPServer module generated directory listings. An attacker able to upload a file with a specially-crafted name to a server could possibly perform a cross-site scripting attack against victims visiting a listing page generated by SimpleHTTPServer, for a directory containing the crafted file. A race condition was found in the way the Python distutils module set file permissions during the creation of the.pypirc file. Various other issues were also addressed.

Weiterlesen...
 

Ähnliche Themen

Mandriva Linux Security Advisory 2012-096

Mandriva Linux Security Advisory 2012-184

Mandriva Linux Security Advisory 2012-184

Red Hat Security Advisory 2012-1590-01

Mandriva Linux Security Advisory 2012-176

Zurück
Oben