-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ## ## Patch description of patch 5eeac52472f698f9b7d58fdd1ad968ce ## Kind: security Shortdescription.english: Security update for python Longdescription.english: Applies to Package: python Product(s): Release: 20050207 Obsoletes: none Indications Everyone using pathon should update. Contraindications None. Problem description This update fixes a bug in the SimpleXMLRPCServer which affects any programs which allows remote untrusted users to do unrestricted traversal. The vulnerability can be used to access and change internal functions. (CAN-2005-0089) Solution Please install the updates provided at the location noted below. Installation notes This update is provided as an RPM package that can easily be installed onto a running system by using this command: rpm -Fvh python.rpm Hsilgne.noitpircsedgnol: Size: 2607 MinYaST1Version: MinYaST2Version: UpdateOnlyInstalled: true Packages: ## ## -----> python <----- ## Filename: python.rpm Label: Python Interpreter Series: i586 Size: 12072499 2670570 PatchRpmBasedOn: 2.2.1-68 PatchRpmSize: 12072499 803654 Buildtime: 1107445908 DepAND: DepOR: DepExcl: Flag: Category: RpmGroup: Development/Languages/Python Copyright: Python AuthorName: Guido van Rossum AuthorAddress: Version: 2.2.1-188 StartCommand: Obsoletes: Requires: /bin/sh /usr/bin/env /usr/bin/python ld-linux.so.2 libc.so.6 libc.so.6(GLIBC_2.0) libc.so.6(GLIBC_2.1) libc.so.6(GLIBC_2.1.2) libc.so.6(GLIBC_2.1.3) libc.so.6(GLIBC_2.2) libcrypt.so.1 libcrypt.so.1(GLIBC_2.0) libcrypto.so.0.9.6 libdl.so.2 libdl.so.2(GLIBC_2.0) libdl.so.2(GLIBC_2.1) libgdbm.so.2 libm.so.6 libm.so.6(GLIBC_2.0) libncurses.so.5 libnsl.so.1 libnsl.so.1(GLIBC_2.0) libpthread.so.0 libpthread.so.0(GLIBC_2.0) libpthread.so.0(GLIBC_2.1) libpthread.so.0(GLIBC_2.2) libreadline.so.4 libssl.so.0.9.6 libutil.so.1 libutil.so.1(GLIBC_2.0) libz.so.1 rpmlib(PayloadIsBzip2) <= 3.0.5-1 Provides: python _codecs.so _hotshot.so _locale.so _socket.so _testcapi.so _weakref.so array.so audioop.so binascii.so cPickle.so cStringIO.so cmath.so crypt.so dbm.so errno.so fcntl.so fpectl.so grp.so imageop.so linuxaudiodev.so math.so md5.so mmap.so nis.so operator.so parser.so pcre.so pwd.so readline.so regex.so resource.so rgbimg.so rotor.so select.so sha.so strop.so struct.so syslog.so termios.so time.so timing.so unicodedata.so xreadlines.so zlib.so Segakcap: -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFCEhOEqE7a6JyACsoRAiA1AJ9Y4K35FYIQscYRO03EoER/5bc2YACf SkuOspNucs3A9howygIAH0uK3rA= =MfFO -----END PGP SIGNATURE-----