Lucene search

K
osvGoogleOSV:DSA-2880-1
HistoryMar 17, 2014 - 12:00 a.m.

python2.7 - security update

2014-03-1700:00:00
Google
osv.dev
11

0.53 Medium

EPSS

Percentile

97.6%

Multiple security issues were discovered in Python:

  • CVE-2013-4238
    Ryan Sleevi discovered that NULL characters in the subject alternate
    names of SSL cerficates were parsed incorrectly.
  • CVE-2014-1912
    Ryan Smith-Roberts discovered a buffer overflow in the
    socket.recvfrom_into() function.

For the stable distribution (wheezy), these problems have been fixed in
version 2.7.3-6+deb7u2.

For the unstable distribution (sid), these problems have been fixed in
version 2.7.6-7.

We recommend that you upgrade your python2.7 packages.

CPENameOperatorVersion
python2.7eq2.7.3-6+deb7u1
python2.7eq2.7.3-6