Lucene search

K
ubuntuUbuntuUSN-430-1
HistoryMar 06, 2007 - 12:00 a.m.

mod_python vulnerability

2007-03-0600:00:00
ubuntu.com
34

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

69.9%

Releases

  • Ubuntu 6.06
  • Ubuntu 5.10

Details

Miles Egan discovered that mod_python, when used in output filter mode,
did not handle output larger than 16384 bytes, and would display freed
memory, possibly disclosing private data. Thanks to Jim Garrison of the
Software Freedom Law Center for identifying the original bug as a
security vulnerability.

OSVersionArchitecturePackageVersionFilename
Ubuntu6.06noarchlibapache2-mod-python< 3.1.4-0ubuntu1.1UNKNOWN
Ubuntu5.10noarchlibapache2-mod-python< 3.1.3-3ubuntu1.1UNKNOWN

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.3

Confidence

Low

EPSS

0.003

Percentile

69.9%