MGASA-2013-0224
Dashboard / Vulnerabilities / MGASA-2013-0224
Summary: Updated python-suds package fixes security vulnerability
Details: An insecure temporary directory use flaw was found in the way python-suds performed initialization of its internal file-based URL cache (predictable location was used for directory to store the cached files). A local attacker could use this flaw to conduct symbolic link attacks, possibly leading to their ability for example the SOAP .wsdl metadata to redirect queries to a different host, than originally intended (CVE-2013-2217).
References: https://advisories.mageia.org/MGASA-2013-0224.html, https://bugs.mageia.org/show_bug.cgi?id=10791, http://lists.opensuse.org/opensuse-updates/2013-07/msg00062.html
Affected packages
Package
Name: python-suds
Purl: pkg:rpm/mageia/python-suds?arch=source&distro=mageia-2
Affected ranges
Type: ECOSYSTEM
Events:
