Oval Definition:oval:com.redhat.rhsa:def:20050100
Revision Date:2005-02-15Version:502
Title:RHSA-2005:100: mod_python security update (Moderate)
Description:Mod_python is a module that embeds the Python language interpreter within the Apache web server, allowing handlers to be written in Python.

Graham Dumpleton discovered a flaw affecting the publisher handler of mod_python, used to make objects inside modules callable via URL. A remote user could visit a carefully crafted URL that would gain access to objects that should not be visible, leading to an information leak. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0088 to this issue.

Users of mod_python are advised to upgrade to this updated package, which contains a backported patch to correct this issue.
Family:unixClass:patch
Status:Reference(s):CVE-2005-0088
RHSA-2005:100-01
Platform(s):Red Hat Enterprise Linux 4
Product(s):
Definition Synopsis
  • Red Hat Enterprise Linux 4 is installed
  • AND mod_python is earlier than 0:3.1.3-5.1
  • AND mod_python is signed with Red Hat master key
  • BACK