Your message dated Sat, 20 Dec 2008 15:32:12 +0000
with message-id <e1le3ok-0003h8...@ries.debian.org>
and subject line Bug#507317: fixed in python2.4 2.4.6-1
has caused the Debian Bug report #507317,
regarding python2.4: CVE-2008-5031 multiple integer overflows
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ow...@bugs.debian.org
immediately.)
--
507317: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=507317
Debian Bug Tracking System
Contact ow...@bugs.debian.org with problems
--- Begin Message ---
Package: python2.4
Version: 2.4.4-3+etch2
Severity: grave
Tags: security patch
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for python2.4.
CVE-2008-5031[0]:
| Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6,
| allow context-dependent attackers to have an unknown impact via a
| large integer value in the tabsize argument to the expandtabs method,
| as implemented by (1) the string_expandtabs function in
| Objects/stringobject.c and (2) the unicode_expandtabs function in
| Objects/unicodeobject.c. NOTE: this vulnerability reportedly exists
| because of an incomplete fix for CVE-2008-2315.
If you fix the vulnerability please also make sure to include the
CVE id in your changelog entry.
verified on stable/testing/unstable. Upstream patches:
http://svn.python.org/view/python/trunk/Objects/unicodeobject.c?p2=%2Fpython%2Ftrunk%2FObjects%2Funicodeobject.c&p1=python%2Ftrunk%2FObjects%2Funicodeobject.c&r1=61350&r2=61349&rev=61350&view=diff&diff_format=u
http://svn.python.org/view/python/trunk/Objects/stringobject.c?p2=%2Fpython%2Ftrunk%2FObjects%2Fstringobject.c&p1=python%2Ftrunk%2FObjects%2Fstringobject.c&r1=61350&r2=61349&rev=61350&view=diff&diff_format=u
For further information see:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5031
http://security-tracker.debian.net/tracker/CVE-2008-5031
--
Nico Golde - http://www.ngolde.de - n...@jabber.ccc.de - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
pgpeXLfTnAB7a.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Source: python2.4
Source-Version: 2.4.6-1
We believe that the bug you reported is fixed in the latest version of
python2.4, which is due to be installed in the Debian FTP archive:
idle-python2.4_2.4.6-1_all.deb
to pool/main/p/python2.4/idle-python2.4_2.4.6-1_all.deb
python2.4-dbg_2.4.6-1_i386.deb
to pool/main/p/python2.4/python2.4-dbg_2.4.6-1_i386.deb
python2.4-dev_2.4.6-1_i386.deb
to pool/main/p/python2.4/python2.4-dev_2.4.6-1_i386.deb
python2.4-examples_2.4.6-1_all.deb
to pool/main/p/python2.4/python2.4-examples_2.4.6-1_all.deb
python2.4-minimal_2.4.6-1_i386.deb
to pool/main/p/python2.4/python2.4-minimal_2.4.6-1_i386.deb
python2.4_2.4.6-1.diff.gz
to pool/main/p/python2.4/python2.4_2.4.6-1.diff.gz
python2.4_2.4.6-1.dsc
to pool/main/p/python2.4/python2.4_2.4.6-1.dsc
python2.4_2.4.6-1_i386.deb
to pool/main/p/python2.4/python2.4_2.4.6-1_i386.deb
python2.4_2.4.6.orig.tar.gz
to pool/main/p/python2.4/python2.4_2.4.6.orig.tar.gz
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 507...@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Matthias Klose <d...@debian.org> (supplier of updated python2.4 package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmas...@debian.org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Format: 1.8
Date: Sat, 20 Dec 2008 15:40:44 +0100
Source: python2.4
Binary: python2.4 python2.4-minimal python2.4-examples python2.4-dev
idle-python2.4 python2.4-doc python2.4-dbg
Architecture: source all i386
Version: 2.4.6-1
Distribution: unstable
Urgency: medium
Maintainer: Matthias Klose <d...@debian.org>
Changed-By: Matthias Klose <d...@debian.org>
Description:
idle-python2.4 - An IDE for Python (v2.4) using Tkinter
python2.4 - An interactive high-level object-oriented language (version 2.4)
python2.4-dbg - Debug Build of the Python Interpreter (version 2.4)
python2.4-dev - Header files and a static library for Python (v2.4)
python2.4-doc - Documentation for the high-level object-oriented language
Python
python2.4-examples - Examples for the Python language (v2.4)
python2.4-minimal - A minimal subset of the Python language (version 2.4)
Closes: 489648 507317
Changes:
python2.4 (2.4.6-1) unstable; urgency=medium
.
* New upstream release (security fixes only).
- Prevent expandtabs() on string and unicode objects from causing a
segfault when a large width is passed on 32-bit platforms.
CVE-2008-5031. Closes: #507317.
- Remove patches applied upstream.
* Avoid bashisms in example script. Closes: #489648.
* Don't include extensions in the package, which did fail to build.
Checksums-Sha1:
5f7da20c20fb1137581b16456d58dc2ab0450566 1606 python2.4_2.4.6-1.dsc
514e6be857e9cbe461806816a7024aab0db10aa8 9594954 python2.4_2.4.6.orig.tar.gz
df8552b136c798517be4df4ef1ea0b86e5ed9dce 225028 python2.4_2.4.6-1.diff.gz
36c00addef7377662bfbc1dcbab37a4e206d966b 593518
python2.4-examples_2.4.6-1_all.deb
aa7d77d1c83c5ae030b3fa568d0dd6db03711bba 63886 idle-python2.4_2.4.6-1_all.deb
01ff9a09f7203b8473ae44f3daa91cd37462ea81 2844482 python2.4_2.4.6-1_i386.deb
d57ad154492659c9743a90df7d6e0632d2c42d42 999772
python2.4-minimal_2.4.6-1_i386.deb
809987165723b0770af460cd783b11f4b85cb9fb 1498854 python2.4-dev_2.4.6-1_i386.deb
5b07a4b9f97b2c2806be831a9de30496cb729ccf 6472296 python2.4-dbg_2.4.6-1_i386.deb
Checksums-Sha256:
d04c9e741831f20cebaeb0925f685751afebc57c4ff2bdcae1bb4d422361f93e 1606
python2.4_2.4.6-1.dsc
855c5fb882b1f6e8a061603b0207485bd86407864f4de60a45df588903e3f95d 9594954
python2.4_2.4.6.orig.tar.gz
11f9b2e1b6f02f40be6df8c30bdb46a5ecfea245c445a19c61ee0c214051558a 225028
python2.4_2.4.6-1.diff.gz
73a12fd495f4e7e1412216e5c09440cc7704cc019301974d360b4cd841c7bbd5 593518
python2.4-examples_2.4.6-1_all.deb
e41f0b39be4017aa68df57e3535bb78deb175b729fd458abfe89b9fa0b312051 63886
idle-python2.4_2.4.6-1_all.deb
89bea011d56b341b8c715f51ee313ecf6ca52b5abd3f5345abaf9e87b2fd5907 2844482
python2.4_2.4.6-1_i386.deb
4905583497a5e3a026f60b28b78c06da5f51eb64a85d1abdec647e3bada2a6ec 999772
python2.4-minimal_2.4.6-1_i386.deb
a115af4739188200fdc32725d757a621eeadd5e4f4d6b2739435ecbbb356f33e 1498854
python2.4-dev_2.4.6-1_i386.deb
2d081579004ad73a67750dfc14edc51c53127921d97419d9d1819bc16bfd85c9 6472296
python2.4-dbg_2.4.6-1_i386.deb
Files:
d8fe259891fddb3e06c7c608740e7f1d 1606 python optional python2.4_2.4.6-1.dsc
1f81e15ea22838260d5c094d31107443 9594954 python optional
python2.4_2.4.6.orig.tar.gz
09ad5626bbe6a4e228cf2b7c40710ecb 225028 python optional
python2.4_2.4.6-1.diff.gz
a6249fc0c1b18733fc228d8df987120e 593518 python optional
python2.4-examples_2.4.6-1_all.deb
38b9a8634d66c02845236b8a095d15a1 63886 python optional
idle-python2.4_2.4.6-1_all.deb
11c377f40d1f3c1f1dadee3f041da0b3 2844482 python optional
python2.4_2.4.6-1_i386.deb
04a9d33537fc9b6d7c8ecc1e20d8d7bb 999772 python optional
python2.4-minimal_2.4.6-1_i386.deb
503ffb457a628f74b057c21354e3fb0f 1498854 python optional
python2.4-dev_2.4.6-1_i386.deb
5b3221a9c0324252a1e6fe22d2498e23 6472296 python extra
python2.4-dbg_2.4.6-1_i386.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
iEYEARECAAYFAklNCuEACgkQStlRaw+TLJyMKQCfQQpV9tk4pLEllZcZ3c/bhk7U
qeUAn0qQgpgmW81Deoh1KmrVyBQO15jx
=DvRs
-----END PGP SIGNATURE-----
--- End Message ---