Advisories ยป MGASA-2015-0091

Updated python packages fix CVE-2014-9365

Publication date: 05 Mar 2015
Modification date: 05 Mar 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-9365

Description

Updated python packages fix security vulnerability:

When Python's standard library HTTP clients (httplib, urllib, urllib2,
xmlrpclib) are used to access resources with HTTPS, by default the certificate
is not checked against any trust store, nor is the hostname in the certificate
checked against the requested host. It was possible to configure a trust root
to be checked against, however there were no faculties for hostname checking
(CVE-2014-9365).

Note that this issue also affects python3, and is fixed upstream in version
3.4.3, but the fix was considered too intrusive to backport to Python3 3.3.x.
No update for the python3 package for this issue is planned at this time.
                

References

SRPMS

4/core