openSUSE Security Update : python (openSUSE-SU-2014:0380-1)

high Nessus Plugin ID 75294

Synopsis

The remote openSUSE host is missing a security update.

Description

Python was updated to 2.7.6 to fix bugs and security issues :

- bugfix-only release

- SSL-related fixes

- upstream fix for CVE-2013-4238

- upstream fixes for CVE-2013-1752

- added patches for CVE-2013-1752 (bnc#856836) issues that are missing in 2.7.6: python-2.7.6-imaplib.patch python-2.7.6-poplib.patch smtplib_maxline-2.7.patch

- CVE-2013-1753 (bnc#856835) gzip decompression bomb in xmlrpc client: xmlrpc_gzip_27.patch

- python-2.7.6-bdist-rpm.patch: fix broken 'setup.py bdist_rpm' command (bnc#857470, issue18045)

- multilib patch: add '~/.local/lib64' paths to search path (bnc#637176)

- CVE-2014-1912-recvfrom_into.patch: fix potential buffer overflow in socket.recvfrom_into (CVE-2014-1912, bnc#863741)

- Add Obsoletes/Provides for python-ctypes.

- reintroduce audioop.so as the problems with it seem to be fixed (bnc#831442)

Solution

Update the affected python packages.

See Also

https://bugzilla.novell.com/show_bug.cgi?id=637176

https://bugzilla.novell.com/show_bug.cgi?id=831442

https://bugzilla.novell.com/show_bug.cgi?id=856835

https://bugzilla.novell.com/show_bug.cgi?id=856836

https://bugzilla.novell.com/show_bug.cgi?id=857470

https://bugzilla.novell.com/show_bug.cgi?id=863741

https://lists.opensuse.org/opensuse-updates/2014-03/msg00044.html

Plugin Details

Severity: High

ID: 75294

File Name: openSUSE-2014-213.nasl

Version: 1.9

Type: local

Agent: unix

Published: 6/13/2014

Updated: 1/19/2021

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.4

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: p-cpe:/a:novell:opensuse:libpython2_7-1_0, p-cpe:/a:novell:opensuse:libpython2_7-1_0-32bit, p-cpe:/a:novell:opensuse:libpython2_7-1_0-debuginfo, p-cpe:/a:novell:opensuse:libpython2_7-1_0-debuginfo-32bit, p-cpe:/a:novell:opensuse:python, p-cpe:/a:novell:opensuse:python-32bit, p-cpe:/a:novell:opensuse:python-base, p-cpe:/a:novell:opensuse:python-base-32bit, p-cpe:/a:novell:opensuse:python-base-debuginfo, p-cpe:/a:novell:opensuse:python-base-debuginfo-32bit, p-cpe:/a:novell:opensuse:python-base-debugsource, p-cpe:/a:novell:opensuse:python-curses, p-cpe:/a:novell:opensuse:python-curses-debuginfo, p-cpe:/a:novell:opensuse:python-debuginfo, p-cpe:/a:novell:opensuse:python-debuginfo-32bit, p-cpe:/a:novell:opensuse:python-debugsource, p-cpe:/a:novell:opensuse:python-demo, p-cpe:/a:novell:opensuse:python-devel, p-cpe:/a:novell:opensuse:python-doc-pdf, p-cpe:/a:novell:opensuse:python-gdbm, p-cpe:/a:novell:opensuse:python-gdbm-debuginfo, p-cpe:/a:novell:opensuse:python-idle, p-cpe:/a:novell:opensuse:python-tk, p-cpe:/a:novell:opensuse:python-tk-debuginfo, p-cpe:/a:novell:opensuse:python-xml, p-cpe:/a:novell:opensuse:python-xml-debuginfo, cpe:/o:novell:opensuse:13.1

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/8/2014

Vulnerability Publication Date: 8/18/2013

Reference Information

CVE: CVE-2013-1752, CVE-2013-1753, CVE-2013-4238, CVE-2014-1912