Bug 758905 (CVE-2011-4944)
Summary: | CVE-2011-4944 python: distutils creates ~/.pypirc insecurely | ||||||
---|---|---|---|---|---|---|---|
Product: | [Other] Security Response | Reporter: | Vincent Danen <vdanen> | ||||
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
Status: | CLOSED ERRATA | QA Contact: | |||||
Severity: | low | Docs Contact: | |||||
Priority: | low | ||||||
Version: | unspecified | CC: | derks, dmalcolm, ivazqueznet, jonathansteffan | ||||
Target Milestone: | --- | Keywords: | Reopened, Security | ||||
Target Release: | --- | ||||||
Hardware: | All | ||||||
OS: | Linux | ||||||
URL: | http://bugs.python.org/issue13512 | ||||||
Whiteboard: | |||||||
Fixed In Version: | Doc Type: | Bug Fix | |||||
Doc Text: | Story Points: | --- | |||||
Clone Of: | Environment: | ||||||
Last Closed: | 2012-07-03 15:42:56 UTC | Type: | --- | ||||
Regression: | --- | Mount Type: | --- | ||||
Documentation: | --- | CRM: | |||||
Verified Versions: | Category: | --- | |||||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
Cloudforms Team: | --- | Target Upstream Version: | |||||
Embargoed: | |||||||
Bug Depends On: | 805382, 805383, 805384, 805385, 808303, 808304, 808305 | ||||||
Bug Blocks: | 790031 | ||||||
Attachments: |
|
Description
Vincent Danen
2011-11-30 23:09:53 UTC
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. Also, the pypi support seems to only be available in python 2.6 and higher, so earlier versions are unaffected. I've reported this upstream: http://bugs.python.org/issue13512 I don't believe this issue is significant enough (particularly due to the default of home directories being mode 0700) to warrant more than that. Upstream patch to go into 2.7.4: http://bugs.python.org/file23824/pypirc-secure.diff This does in fact affect RHEL5 and earlier; the vulnerable code is in Lib/distutils/command/register.py. Created attachment 573152 [details]
proposed patch to correct the flaw
This patch should correct the flaw in python 2.4.x.
Corrected CVE number as per http://www.openwall.com/lists/oss-security/2012/03/27/10 Created python tracking bugs for this issue Affects: fedora-all [bug 808303] Created python3 tracking bugs for this issue Affects: fedora-all [bug 808304] Created python26 tracking bugs for this issue Affects: epel-5 [bug 808305] This issue has been addressed in following products: Red Hat Enterprise Linux 6 Via RHSA-2012:0744 https://rhn.redhat.com/errata/RHSA-2012-0744.html This issue has been addressed in following products: Red Hat Enterprise Linux 5 Via RHSA-2012:0745 https://rhn.redhat.com/errata/RHSA-2012-0745.html |