Oval Definition:oval:com.redhat.rhsa:def:20131582
Revision Date:2013-11-21Version:643
Title:RHSA-2013:1582: python security, bug fix, and enhancement update (Moderate)
Description:Python is an interpreted, interactive, object-oriented programming language.

  • A flaw was found in the way the Python SSL module handled X.509 certificate fields that contain a NULL byte. An attacker could potentially exploit this flaw to conduct man-in-the-middle attacks to spoof SSL servers. Note that to exploit this issue, an attacker would need to obtain a carefully crafted certificate signed by an authority that the client trusts. (CVE-2013-4238)

    These updated python packages include numerous bug fixes and one enhancement. Space precludes documenting all of these changes in this advisory. Users are directed to the Red Hat Enterprise Linux 6.5 Technical Notes, linked to in the References, for information on the most significant of these changes.

    All users of python are advised to upgrade to these updated packages, which fix these issues and add this enhancement.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-4238
    CVE-2013-4238
    RHSA-2013:1582
    RHSA-2013:1582-02
    RHSA-2013:1582-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • python is earlier than 0:2.6.6-51.el6
  • AND python is signed with Red Hat redhatrelease2 key
  • python-devel is earlier than 0:2.6.6-51.el6
  • AND python-devel is signed with Red Hat redhatrelease2 key
  • python-libs is earlier than 0:2.6.6-51.el6
  • AND python-libs is signed with Red Hat redhatrelease2 key
  • python-test is earlier than 0:2.6.6-51.el6
  • AND python-test is signed with Red Hat redhatrelease2 key
  • python-tools is earlier than 0:2.6.6-51.el6
  • AND python-tools is signed with Red Hat redhatrelease2 key
  • tkinter is earlier than 0:2.6.6-51.el6
  • AND tkinter is signed with Red Hat redhatrelease2 key
  • BACK