ALAS-2014-440 ---- python27ID: oval:org.secpod.oval:def:1600002 | Date: (C)2016-01-19 (M)2024-04-17 |
Class: PATCH | Family: unix |
It was discovered that Python built-in module CGIHTTPServer does not properly handle URL-encoded path separators in URLs which may enable attackers to disclose a CGI script"s source code or execute arbitrary scripts in the server"s document root. Integer overflow in bufferobject.c in Python before 2.7.8 allows context-dependent attackers to obtain sensitive information from process memory via a large size and offset in a "buffer" function
Platform: |
Amazon Linux AMI |