MGASA-2014-0216
Dashboard / Vulnerabilities / MGASA-2014-0216
Summary: Updated python3 packages fix security vulnerability
Details: It was reported that a patch added to Python 3.2 caused a race condition where a file created could be created with world read/write permissions instead of the permissions dictated by the original umask of the process. This could allow a local attacker that could win the race to view and edit files created by a program using this call. Note that prior versions of Python, including 2.x, do not include the vulnerable _get_masked_mode() function that is used by os.makedirs() when exist_ok is set to True (CVE-2014-2667).
References: https://advisories.mageia.org/MGASA-2014-0216.html, https://bugs.mageia.org/show_bug.cgi?id=13305, http://lists.opensuse.org/opensuse-updates/2014-05/msg00007.html
Affected packages
Package
Name: python3
Purl: pkg:rpm/mageia/python3?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
