-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
_______________________________________________________________________
Mandriva Linux Security Advisory MDVSA-2015:075
http://www.mandriva.com/en/support/security/
_______________________________________________________________________
Package : python
Date : March 27, 2015
Affected: Business Server 2.0
_______________________________________________________________________
Problem Description:
Updated python packages fix security vulnerabilities:
A vulnerability was reported in Python's socket module, due to
a boundary error within the sock_recvfrom_into() function, which
could be exploited to cause a buffer overflow. This could be used
to crash a Python application that uses the socket.recvfrom_info()
function or, possibly, execute arbitrary code with the permissions
of the user running vulnerable Python code (CVE-2014-1912).
This updates the python package to version 2.7.6, which fixes several
other