[ MDVSA-2015:180 ] apache-mod_wsgi

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2015:180
 http://www.mandriva.com/en/support/security/
 _______________________________________________________________________

 Package : apache-mod_wsgi
 Date    : March 30, 2015
 Affected: Business Server 2.0
 _______________________________________________________________________

 Problem Description:

 Updated apache-mod_wsgi package fixes security vulnerabilities:
 
 apache-mod_wsgi before 4.2.4 contained an off-by-one error in
 applying a limit to the number of supplementary groups allowed for
 a daemon process group. The result could be that if more groups
 than the operating system allowed were specified to the option
 supplementary-groups, then memory corruption or a process crash
 could occur.
 
 It was discovered that mod_wsgi incorrectly handled errors when
 setting up the working directory and group access righ

Leave a Reply