Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2015-01348

Опубликовано: 04 окт. 2002
Источник: fstec
CVSS2: 4.6
EPSS Низкий

Описание

Множественные уязвимости пакета idle операционной системы Debian GNU/Linux, эксплуатация которых может привести к нарушению конфиденциальности, целостности и доступности защищаемой информации.

Вендор

Сообщество свободного программного обеспечения

Наименование ПО

Debian GNU/Linux

Версия ПО

до 3.0 (Debian GNU/Linux)

Тип ПО

Операционная система

Операционные системы и аппаратные платформы

-

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 4,6)

Возможные меры по устранению уязвимости

Проблема может быть решена обновлением операционной системы до следующих версий пакетов в зависимости от архитектуры:
Debian GNU/Linux 3.0:
ppc:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
s390x:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
m68k:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
i686:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
hppa:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
sparc:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
alpha:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
ia64:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
mips:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
noarch:
idle-python1.5 - 1.5.2-23.2
python1.5-examples - 1.5.2-23.2
idle-python2.1 - 2.1.3-3.2
idle - 2.1.3-3.2
python-dev - 2.1.3-3.2
python-doc - 2.1.3-3.2
python-elisp - 2.1.3-3.2
python-examples - 2.1.3-3.2
python-gdbm - 2.1.3-3.2
python-mpz - 2.1.3-3.2
python-tk - 2.1.3-3.2
python-xmlbase - 2.1.3-3.2
python2.1-doc - 2.1.3-3.2
python2.1-elisp - 2.1.3-3.2
python2.1-examples - 2.1.3-3.2
python - 2.1.3-3.2
idle-python2.2 - 2.2.1-4.2
python2.2-doc - 2.2.1-4.2
python2.2-elisp - 2.2.1-4.2
python2.2-examples - 2.2.1-4.2
mipsel:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
arm:
python1.5 - 1.5.2-23.2
python1.5-dev - 1.5.2-23.2
python1.5-gdbm - 1.5.2-23.2
python1.5-mpz - 1.5.2-23.2
python1.5-tk - 1.5.2-23.2
python2.1 - 2.1.3-3.2
python2.1-dev - 2.1.3-3.2
python2.1-gdbm - 2.1.3-3.2
python2.1-mpz - 2.1.3-3.2
python2.1-tk - 2.1.3-3.2
python2.1-xmlbase - 2.1.3-3.2
python2.2 - 2.2.1-4.2
python2.2-dev - 2.2.1-4.2
python2.2-gdbm - 2.2.1-4.2
python2.2-mpz - 2.2.1-4.2
python2.2-tk - 2.2.1-4.2
python2.2-xmlbase - 2.2.1-4.2
Debian GNU/Linux 2.2:
ppc:
python-base - 1.5.2-10potato13
python-dev - 1.5.2-10potato13
python-gdbm - 1.5.2-10potato13
python-mpz - 1.5.2-10potato13
python-tk - 1.5.2-10potato13
python-zlib - 1.5.2-10potato13
m68k:
python-base - 1.5.2-10potato13
python-dev - 1.5.2-10potato13
python-gdbm - 1.5.2-10potato13
python-mpz - 1.5.2-10potato13
python-tk - 1.5.2-10potato13
python-zlib - 1.5.2-10potato13
noarch:
idle - 1.5.2-10potato13
python-elisp - 1.5.2-10potato13
python-examples - 1.5.2-10potato13
python-regrtest - 1.5.2-10potato13
sparc:
python-base - 1.5.2-10potato13
python-dev - 1.5.2-10potato13
python-gdbm - 1.5.2-10potato13
python-mpz - 1.5.2-10potato13
python-tk - 1.5.2-10potato13
python-zlib - 1.5.2-10potato13
alpha:
python-base - 1.5.2-10potato13
python-dev - 1.5.2-10potato13
python-gdbm - 1.5.2-10potato13
python-mpz - 1.5.2-10potato13
python-tk - 1.5.2-10potato13
python-zlib - 1.5.2-10potato13
i686:
python-base - 1.5.2-10potato13
python-dev - 1.5.2-10potato13
python-gdbm - 1.5.2-10potato13
python-mpz - 1.5.2-10potato13
python-tk - 1.5.2-10potato13
python-zlib - 1.5.2-10potato13
arm:
python-base - 1.5.2-10potato13
python-dev - 1.5.2-10potato13
python-gdbm - 1.5.2-10potato13
python-mpz - 1.5.2-10potato13
python-tk - 1.5.2-10potato13
python-zlib - 1.5.2-10potato13

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 36%
0.00144
Низкий

4.6 Medium

CVSS2

Связанные уязвимости

redhat
почти 23 года назад

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

nvd
больше 22 лет назад

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

debian
больше 22 лет назад

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary f ...

github
около 3 лет назад

os._execvpe from os.py in Python 2.2.1 and earlier creates temporary files with predictable names, which could allow local users to execute arbitrary code via a symlink attack.

EPSS

Процентиль: 36%
0.00144
Низкий

4.6 Medium

CVSS2