Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2004:019: python Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the python package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2004:019 (python).
A buffer overflow in python 2.2's getaddrinfo() function was discovered by
Sebastian Schmidt. If python 2.2 is built without IPv6 support, a possible hacker
could configure their name server to let a hostname resolve to a special IPv6
address, which could contain a memory address where shellcode is placed. This
problem does not affect python versions prior to 2.2 or versions 2.2.2+, and it
also doesn't exist if IPv6 support is enabled.
The updated packages have been patched to correct the problem. Thanks to
Sebastian for both the discovery and patch.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2004:019
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.