Oval Definition:oval:com.redhat.rhsa:def:20121206
Revision Date:2012-08-27Version:634
Title:RHSA-2012:1206: python-paste-script security update (Moderate)
Description:Python Paste provides middleware for building and running Python web applications. The python-paste-script package includes paster, a tool for working with and running Python Paste applications.

  • It was discovered that paster did not drop supplementary group privileges when started by the root user. Running "paster serve" as root to start a Python web application that will run as a non-root user and group resulted in that application running with root group privileges. This could possibly allow a remote attacker to gain access to files that should not be accessible to the application. (CVE-2012-0878)

    All paster users should upgrade to this updated package, which contains a backported patch to resolve this issue. All running paster instances configured to drop privileges must be restarted for this update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-0878
    CVE-2012-0878
    RHSA-2012:1206
    RHSA-2012:1206-01
    RHSA-2012:1206-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND python-paste-script is earlier than 0:1.7.3-5.el6_3
  • AND python-paste-script is signed with Red Hat redhatrelease2 key
  • BACK