[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2014-440 ---- python27

ID: oval:org.secpod.oval:def:1600002Date: (C)2016-01-19   (M)2024-04-17
Class: PATCHFamily: unix




It was discovered that Python built-in module CGIHTTPServer does not properly handle URL-encoded path separators in URLs which may enable attackers to disclose a CGI script"s source code or execute arbitrary scripts in the server"s document root. Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function

Platform:
Amazon Linux AMI
Product:
python27
Reference:
ALAS-2014-440
CVE-2014-7185
CVE-2014-4650
CVE    2
CVE-2014-4650
CVE-2014-7185
CPE    2
cpe:/o:amazon:linux
cpe:/a:python:python27

© SecPod Technologies