exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Mandriva Linux Security Advisory 2009-049

Mandriva Linux Security Advisory 2009-049
Posted Feb 21, 2009
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2009-049 - A vulnerability have been discovered and corrected in PyCrypto ARC2 module 2.0.1, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length. The updated packages have been patched to prevent this.

tags | advisory, remote, denial of service, arbitrary
systems | linux, mandriva
advisories | CVE-2009-0544
SHA-256 | 3923acde3f1a836723a8881c22bc76c76cb69ad9e9dca5bb16749cc0b8cd3809

Mandriva Linux Security Advisory 2009-049

Change Mirror Download

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2009:049
http://www.mandriva.com/security/
_______________________________________________________________________

Package : pycrypto
Date : February 20, 2009
Affected: 2008.0, 2008.1, 2009.0, Corporate 4.0
_______________________________________________________________________

Problem Description:

A vulnerability have been discovered and corrected in PyCrypto
ARC2 module 2.0.1, which allows remote attackers to cause a denial
of service and possibly execute arbitrary code via a large ARC2 key
length (CVE-2009-0544).

The updated packages have been patched to prevent this.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0544
_______________________________________________________________________

Updated Packages:

Mandriva Linux 2008.0:
4de11f080f4dfd01695c0627f02c4c6a 2008.0/i586/pycrypto-2.0.1-1.1mdv2008.0.i586.rpm
1cd88426fcdb24d629b0fb4ec0314ce1 2008.0/SRPMS/pycrypto-2.0.1-1.1mdv2008.0.src.rpm

Mandriva Linux 2008.0/X86_64:
90069f7c2307626f0b09ea93ce1313ab 2008.0/x86_64/pycrypto-2.0.1-1.1mdv2008.0.x86_64.rpm
1cd88426fcdb24d629b0fb4ec0314ce1 2008.0/SRPMS/pycrypto-2.0.1-1.1mdv2008.0.src.rpm

Mandriva Linux 2008.1:
e3897524dbf402bb3b4bf3f0f778b8d5 2008.1/i586/pycrypto-2.0.1-2.1mdv2008.1.i586.rpm
0ec575b2b3972f9dced1b831b2c35fec 2008.1/SRPMS/pycrypto-2.0.1-2.1mdv2008.1.src.rpm

Mandriva Linux 2008.1/X86_64:
512f5b30b52e9b2ab9bad3e98674bb07 2008.1/x86_64/pycrypto-2.0.1-2.1mdv2008.1.x86_64.rpm
0ec575b2b3972f9dced1b831b2c35fec 2008.1/SRPMS/pycrypto-2.0.1-2.1mdv2008.1.src.rpm

Mandriva Linux 2009.0:
88819dec46e49db09a2adec77c6e7144 2009.0/i586/pycrypto-2.0.1-3.1mdv2009.0.i586.rpm
284d315d31be7c9c4653e08b913ba380 2009.0/SRPMS/pycrypto-2.0.1-3.1mdv2009.0.src.rpm

Mandriva Linux 2009.0/X86_64:
a73c8d582e79e88a3b41b146ac137c7d 2009.0/x86_64/pycrypto-2.0.1-3.1mdv2009.0.x86_64.rpm
284d315d31be7c9c4653e08b913ba380 2009.0/SRPMS/pycrypto-2.0.1-3.1mdv2009.0.src.rpm

Corporate 4.0:
a1098e064ef48bbeb7c29bbb3856d20e corporate/4.0/i586/pycrypto-2.0-1.1.20060mlcs4.i586.rpm
2b36370cb7c50e2e97754835685ff5b5 corporate/4.0/SRPMS/pycrypto-2.0-1.1.20060mlcs4.src.rpm

Corporate 4.0/X86_64:
7c44b73cf1fd308b015abd1e7b710972 corporate/4.0/x86_64/pycrypto-2.0-1.1.20060mlcs4.x86_64.rpm
2b36370cb7c50e2e97754835685ff5b5 corporate/4.0/SRPMS/pycrypto-2.0-1.1.20060mlcs4.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/security/advisories

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iD8DBQFJnxSWmqjQ0CJFipgRArbeAJ0ZKypJacu52Jh48WOW6uK5bVozsACgg95N
n6VQX0YdwrbMP/PXRJ/jhd0=
=f/0D
-----END PGP SIGNATURE-----

Login or Register to add favorites

File Archive:

May 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    15 Files
  • 2
    May 2nd
    16 Files
  • 3
    May 3rd
    38 Files
  • 4
    May 4th
    15 Files
  • 5
    May 5th
    35 Files
  • 6
    May 6th
    0 Files
  • 7
    May 7th
    0 Files
  • 8
    May 8th
    8 Files
  • 9
    May 9th
    65 Files
  • 10
    May 10th
    19 Files
  • 11
    May 11th
    27 Files
  • 12
    May 12th
    8 Files
  • 13
    May 13th
    0 Files
  • 14
    May 14th
    1 Files
  • 15
    May 15th
    19 Files
  • 16
    May 16th
    66 Files
  • 17
    May 17th
    28 Files
  • 18
    May 18th
    32 Files
  • 19
    May 19th
    13 Files
  • 20
    May 20th
    0 Files
  • 21
    May 21st
    0 Files
  • 22
    May 22nd
    23 Files
  • 23
    May 23rd
    15 Files
  • 24
    May 24th
    49 Files
  • 25
    May 25th
    20 Files
  • 26
    May 26th
    13 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    11 Files
  • 30
    May 30th
    46 Files
  • 31
    May 31st
    15 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close