Security Advisory python security update

Advisory: RHSA-2005:109-04
Type: Security Advisory
Severity: Important
Issued on: 2005-02-14
Last updated on: 2005-02-14
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
OVAL: N/A
CVEs (cve.mitre.org): CVE-2005-0089

Details

Updated Python packages that fix a security issue are now available for Red
Hat Enterprise Linux 3.

Python is an interpreted, interactive, object-oriented programming language.

An object traversal bug was found in the Python SimpleXMLRPCServer. This
bug could allow a remote untrusted user to do unrestricted object traversal
and allow them to access or change function internals using the im_* and
func_* attributes. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2005-0089 to this issue.

Users of Python are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
python-2.2.3-6.1.src.rpm     e2afdf86efaeca10b9b4087dff1b9699
 
IA-32:
python-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    3d091411b02eb2eabc140aefceab0a70
python-devel-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    f89756adb6fce46bdffb6468c54abc9d
python-tools-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    9dd80af07cebf97c7312fc0abc730678
tkinter-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    279a1687b7c6738b54a9f5b28ce3ebce
 
x86_64:
python-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    de9baec09fa8c45ee1e0318bcde9044c
python-devel-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    448838cec4a4233f560ccbfef6057c76
python-tools-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    f7958aab2797f017311747bde81a1e56
tkinter-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    b917cf0e6fdaf4744d3360004b5fd2c6
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
python-2.2.3-6.1.src.rpm     e2afdf86efaeca10b9b4087dff1b9699
 
IA-32:
python-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    3d091411b02eb2eabc140aefceab0a70
python-devel-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    f89756adb6fce46bdffb6468c54abc9d
python-tools-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    9dd80af07cebf97c7312fc0abc730678
tkinter-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    279a1687b7c6738b54a9f5b28ce3ebce
 
IA-64:
python-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    53357b03643c8a3f4954cf32c9470ab1
python-devel-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    9b8763dba084023eac9b19da8cea964c
python-tools-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    2ce315b8ce5f88ae9a31d09146165987
tkinter-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    779a0440c093e8a00e8b922ac4b743f5
 
PPC:
python-2.2.3-6.1.ppc.rpm
File outdated by:  RHSA-2007:1076
    f96de6b570c9a1d532e99e7982e3ff92
python-devel-2.2.3-6.1.ppc.rpm
File outdated by:  RHSA-2007:1076
    331906ef01b3b670e990ad8850f8b7fb
python-tools-2.2.3-6.1.ppc.rpm
File outdated by:  RHSA-2007:1076
    1b0b8f209cc16934306fb5a15ecc124c
tkinter-2.2.3-6.1.ppc.rpm
File outdated by:  RHSA-2007:1076
    dea04a1a3f652130a43812f376906982
 
s390:
python-2.2.3-6.1.s390.rpm
File outdated by:  RHSA-2007:1076
    252f5743633b8b91a1d00c954fa4dc96
python-devel-2.2.3-6.1.s390.rpm
File outdated by:  RHSA-2007:1076
    450852465e354744bbe430c0af750ee5
python-tools-2.2.3-6.1.s390.rpm
File outdated by:  RHSA-2007:1076
    3b5dcffcbe6088143e2aab3a6ccb2b87
tkinter-2.2.3-6.1.s390.rpm
File outdated by:  RHSA-2007:1076
    a1fa622c4dcfbdebbd79eeb1a7e03859
 
s390x:
python-2.2.3-6.1.s390x.rpm
File outdated by:  RHSA-2007:1076
    a8e73f8eb75b2552c7ec142588974795
python-devel-2.2.3-6.1.s390x.rpm
File outdated by:  RHSA-2007:1076
    cd88f6b8113fdf4b648ba1a95884d528
python-tools-2.2.3-6.1.s390x.rpm
File outdated by:  RHSA-2007:1076
    68bc8ea6ad87e440dc701808345beda0
tkinter-2.2.3-6.1.s390x.rpm
File outdated by:  RHSA-2007:1076
    4990c863d384d099c943f36a1bc7ca92
 
x86_64:
python-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    de9baec09fa8c45ee1e0318bcde9044c
python-devel-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    448838cec4a4233f560ccbfef6057c76
python-tools-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    f7958aab2797f017311747bde81a1e56
tkinter-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    b917cf0e6fdaf4744d3360004b5fd2c6
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
python-2.2.3-6.1.src.rpm     e2afdf86efaeca10b9b4087dff1b9699
 
IA-32:
python-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    3d091411b02eb2eabc140aefceab0a70
python-devel-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    f89756adb6fce46bdffb6468c54abc9d
python-tools-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    9dd80af07cebf97c7312fc0abc730678
tkinter-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    279a1687b7c6738b54a9f5b28ce3ebce
 
IA-64:
python-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    53357b03643c8a3f4954cf32c9470ab1
python-devel-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    9b8763dba084023eac9b19da8cea964c
python-tools-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    2ce315b8ce5f88ae9a31d09146165987
tkinter-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    779a0440c093e8a00e8b922ac4b743f5
 
x86_64:
python-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    de9baec09fa8c45ee1e0318bcde9044c
python-devel-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    448838cec4a4233f560ccbfef6057c76
python-tools-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    f7958aab2797f017311747bde81a1e56
tkinter-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    b917cf0e6fdaf4744d3360004b5fd2c6
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
python-2.2.3-6.1.src.rpm     e2afdf86efaeca10b9b4087dff1b9699
 
IA-32:
python-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    3d091411b02eb2eabc140aefceab0a70
python-devel-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    f89756adb6fce46bdffb6468c54abc9d
python-tools-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    9dd80af07cebf97c7312fc0abc730678
tkinter-2.2.3-6.1.i386.rpm
File outdated by:  RHSA-2007:1076
    279a1687b7c6738b54a9f5b28ce3ebce
 
IA-64:
python-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    53357b03643c8a3f4954cf32c9470ab1
python-devel-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    9b8763dba084023eac9b19da8cea964c
python-tools-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    2ce315b8ce5f88ae9a31d09146165987
tkinter-2.2.3-6.1.ia64.rpm
File outdated by:  RHSA-2007:1076
    779a0440c093e8a00e8b922ac4b743f5
 
x86_64:
python-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    de9baec09fa8c45ee1e0318bcde9044c
python-devel-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    448838cec4a4233f560ccbfef6057c76
python-tools-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    f7958aab2797f017311747bde81a1e56
tkinter-2.2.3-6.1.x86_64.rpm
File outdated by:  RHSA-2007:1076
    b917cf0e6fdaf4744d3360004b5fd2c6
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

146645 - CAN-2005-0089 python SimpleXMLRPCServer security issue


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/