February 2006
Mod_python 3.2.8 (security)
ID: 00160
Ref: 158/2006
Date: 27 February 2006:11:24:57
Version: 1
Title: Mod_python 3.2.8 (security)
Abstract: The Apache Software Foundation and The Apache HTTP Server Project are pleased to announce the release of version 3.2.8 of mod_python.
Vendors affected: Apache
Operating systems affected: Apache
Applications affected: Apache
Title
=====
Mod_python 3.2.8 (security)
Detail
======
The Apache Software Foundation and The Apache HTTP Server Project are
pleased to announce the release of version 3.2.8 of mod_python.
This release addresses a vulnerability in mod_python's FileSession
object whereby a carefully crafted session cookie could potentially
permit an attacker to execute code on the server.
FileSession was introduced in mod_python 3.2.7 released on February 15
2006 and is not enabled by default, therefore only a very small number
of installations, if any, are likely to be affected by this issue.
There are no other changes or improvements from the previous version in
this release.
Mod_python is available for download from:
http://httpd.apache.org/modules/python-download.cgi
For more information about mod_python visit http://www.modpython.org/