Paketname
epiphany
Datum
2009-02-20
Advisory ID
MDVSA-2009:048
Betroffene Versionen
2009.0 x86_64 , 2009.0 i586 , 2008.1 x86_64 , 2008.1 i586

Problembeschreibung

Python has a variable called sys.path that contains all paths where
Python loads modules by using import scripting procedure. A wrong
handling of that variable enables local attackers to execute arbitrary
code via Python scripting in the current Epiphany working directory
(CVE-2008-5985).

This update provides fix for that vulnerability.

Aktualisierte Pakete

2009.0 x86_64

 59f02a533a103c731df648787045ba82  2009.0/x86_64/epiphany-2.24.0.1-3.4mdv2009.0.x86_64.rpm
 04e340d36770c77b9ced0592194b6ac0  2009.0/x86_64/epiphany-devel-2.24.0.1-3.4mdv2009.0.x86_64.rpm 
 1fcdd0b2282f173a9bba98a703a9a547  2009.0/SRPMS/epiphany-2.24.0.1-3.4mdv2009.0.src.rpm

2009.0 i586

 bd178708efd25e7d367742bda02cf9fc  2009.0/i586/epiphany-2.24.0.1-3.4mdv2009.0.i586.rpm
 a5c5a31a18d8dbd30ba8be79969ec7d0  2009.0/i586/epiphany-devel-2.24.0.1-3.4mdv2009.0.i586.rpm 
 1fcdd0b2282f173a9bba98a703a9a547  2009.0/SRPMS/epiphany-2.24.0.1-3.4mdv2009.0.src.rpm

2008.1 x86_64

 b35d75332c54653e6dc2ec41c84a4424  2008.1/x86_64/epiphany-2.22.0-4.7mdv2008.1.x86_64.rpm
 889d95c23ef5afde6eae1ccd98e2433b  2008.1/x86_64/epiphany-devel-2.22.0-4.7mdv2008.1.x86_64.rpm 
 24434a32b8340959ac3a071094d064b7  2008.1/SRPMS/epiphany-2.22.0-4.7mdv2008.1.src.rpm

2008.1 i586

 39b5f6f845204481caf4a2b47c5d0a68  2008.1/i586/epiphany-2.22.0-4.7mdv2008.1.i586.rpm
 92fdad57cb91f6cf722d1e31165d0edf  2008.1/i586/epiphany-devel-2.22.0-4.7mdv2008.1.i586.rpm 
 24434a32b8340959ac3a071094d064b7  2008.1/SRPMS/epiphany-2.22.0-4.7mdv2008.1.src.rpm

Referenzen