Amazon Linux AMI : python26 / python27,python34 (ALAS-2016-724)

critical Nessus Plugin ID 92471

Synopsis

The remote Amazon Linux AMI host is missing a security update.

Description

It was found that Python's httplib library (used urllib, urllib2 and others) did not properly check HTTP header input in HTTPConnection.putheader(). An attacker could use this flow to inject additional headers in a Python application that allows user provided header name or values. (CVE-2016-5699)

It was found that Python's smtplib library did not return an exception if StartTLS fails to establish correctly in the SMTP.starttls() function. An attacker with ability to launch an active man in the middle attack could strip out the STARTTLS command without generating an exception on the python SMTP client application, preventing the establishment of the TLS layer. (CVE-2016-0772)

A vulnerability was discovered in Python, in the built-in zipimporter.
A specially crafted zip file placed in a module path such that it would be loaded by a later 'import' statement could cause a heap overflow, leading to arbitrary code execution. (CVE-2016-5636)

Solution

Run 'yum update python26' to update your system.

Run 'yum update python27' to update your system.

Run 'yum update python34' to update your system.

See Also

https://alas.aws.amazon.com/ALAS-2016-724.html

Plugin Details

Severity: Critical

ID: 92471

File Name: ala_ALAS-2016-724.nasl

Version: 2.5

Type: local

Agent: unix

Published: 7/21/2016

Updated: 4/11/2019

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:python26, p-cpe:/a:amazon:linux:python26-debuginfo, p-cpe:/a:amazon:linux:python26-devel, p-cpe:/a:amazon:linux:python26-libs, p-cpe:/a:amazon:linux:python26-test, p-cpe:/a:amazon:linux:python26-tools, p-cpe:/a:amazon:linux:python27, p-cpe:/a:amazon:linux:python27-debuginfo, p-cpe:/a:amazon:linux:python27-devel, p-cpe:/a:amazon:linux:python27-libs, p-cpe:/a:amazon:linux:python27-test, p-cpe:/a:amazon:linux:python27-tools, p-cpe:/a:amazon:linux:python34, p-cpe:/a:amazon:linux:python34-debuginfo, p-cpe:/a:amazon:linux:python34-devel, p-cpe:/a:amazon:linux:python34-libs, p-cpe:/a:amazon:linux:python34-test, p-cpe:/a:amazon:linux:python34-tools, cpe:/o:amazon:linux

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/20/2016

Reference Information

CVE: CVE-2016-0772, CVE-2016-5636, CVE-2016-5699

ALAS: 2016-724