CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
Percentile
88.5%
CentOS Errata and Security Advisory CESA-2006:0197-01
Python is an interpreted, interactive, object-oriented programming language.
An integer overflow flaw was found in Python’s PCRE library that could be
triggered by a maliciously crafted regular expression. On systems that
accept arbitrary regular expressions from untrusted users, this could be
exploited to execute arbitrary code with the privileges of the application
using the library. The Common Vulnerabilities and Exposures project
assigned the name CVE-2005-2491 to this issue.
Users of Python should upgrade to these updated packages, which contain a
backported patch that is not vulnerable to this issue.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2006-March/074882.html
Affected packages:
python
python-devel
python-docs
python-tools
tkinter
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 2 | i386 | python | < 1.5.2-43.72.1 | python-1.5.2-43.72.1.i386.rpm |
CentOS | 2 | i386 | python-devel | < 1.5.2-43.72.1 | python-devel-1.5.2-43.72.1.i386.rpm |
CentOS | 2 | i386 | python-docs | < 1.5.2-43.72.1 | python-docs-1.5.2-43.72.1.i386.rpm |
CentOS | 2 | i386 | python-tools | < 1.5.2-43.72.1 | python-tools-1.5.2-43.72.1.i386.rpm |
CentOS | 2 | i386 | tkinter | < 1.5.2-43.72.1 | tkinter-1.5.2-43.72.1.i386.rpm |