OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: Python, was: Re: only days left to ports lock (4.4 release)

From: Toni Mueller (openbsd-portsoeko.net)
Date: Tue Aug 05 2008 - 05:45:14 CDT


Hi,

On Tue, 05.08.2008 at 18:36:34 +1000, Damien Miller <djmmindrot.org> wrote:
> Ok, here is a patch for lang/python/2.5.

thank you very much for the effort. Unfortunately, there's some more
stuff which should probably make it (code execution problems included).
I found these just today, assuming that everything up to CVE-2008-2315
is already covered:

CVE-2008-3144 CVE-2008-3143 CVE-2008-3142 CVE-2008-2316

I don't know which of these are already covered, but the first is
labelled "medium", the other "high" in the CVE database.

Kind regards,
--Toni++