Oval Definition:oval:com.redhat.rhsa:def:20100002
Revision Date:2010-01-04Version:642
Title:RHSA-2010:0002: PyXML security update (Moderate)
Description:PyXML provides XML libraries for Python. The distribution contains a validating XML parser, an implementation of the SAX and DOM programming interfaces, and an interface to the Expat parser.

  • A buffer over-read flaw was found in the way PyXML's Expat parser handled malformed UTF-8 sequences when processing XML files. A specially-crafted XML file could cause Python applications using PyXML's Expat parser to crash while parsing the file. (CVE-2009-3720)

    This update makes PyXML use the system Expat library rather than its own internal copy; therefore, users must install the RHSA-2009:1625 expat update together with this PyXML update to resolve the CVE-2009-3720 issue.

    All PyXML users should upgrade to this updated package, which changes PyXML to use the system Expat library. After installing this update along with RHSA-2009:1625, applications using the PyXML library must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-3720
    RHSA-2010:0002
    RHSA-2010:0002-01
    RHSA-2010:0002-01
    Platform(s):Red Hat Enterprise Linux 4
    Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 4 is installed
  • AND PyXML is earlier than 0:0.8.3-6.el4_8.2
  • AND PyXML is signed with Red Hat redhatrelease2 key
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND PyXML is earlier than 0:0.8.4-4.el5_4.2
  • AND PyXML is signed with Red Hat redhatrelease2 key
  • BACK