Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.4.2012.0985.1
Category:SuSE Local Security Checks
Title:SUSE: Security Advisory (SUSE-SU-2012:0985-1)
Summary:The remote host is missing an update for the 'apache2-mod_python' package(s) announced via the SUSE-SU-2012:0985-1 advisory.
Description:Summary:
The remote host is missing an update for the 'apache2-mod_python' package(s) announced via the SUSE-SU-2012:0985-1 advisory.

Vulnerability Insight:
Apache2 mod_python has been changed to enable randomized hashes to help fixing denial of service problems by injecting prepared values into Python hash functions.
(CVE-2012-1150)

As some Python scripts might need a known hashing order,
the old behaviour can be restored using a newly introduced module option called

PythonRandomizeHashes

The option is default on, but can be disabled if necessary for compatibility with above scripts.

Security Issue reference:

* CVE-2012-1150
>

Affected Software/OS:
'apache2-mod_python' package(s) on SUSE Linux Enterprise Server 10-SP4, SUSE Linux Enterprise Server 11-SP1, SUSE Linux Enterprise Server 11-SP2, SUSE Linux Enterprise Software Development Kit 11-SP1, SUSE Linux Enterprise Software Development Kit 11-SP2.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1150
50858
http://secunia.com/advisories/50858
51087
http://secunia.com/advisories/51087
51089
http://secunia.com/advisories/51089
APPLE-SA-2013-10-22-3
http://lists.apple.com/archives/security-announce/2013/Oct/msg00004.html
USN-1592-1
http://www.ubuntu.com/usn/USN-1592-1
USN-1596-1
http://www.ubuntu.com/usn/USN-1596-1
USN-1615-1
http://www.ubuntu.com/usn/USN-1615-1
USN-1616-1
http://www.ubuntu.com/usn/USN-1616-1
[oss-security] 20120309 Re: CVE Request: Python Hash DoS (Issue 13703)
http://www.openwall.com/lists/oss-security/2012/03/10/3
[python-dev] 20111229 Hash collision security issue (now public)
http://mail.python.org/pipermail/python-dev/2011-December/115116.html
[python-dev] 20120128 plugging the hash attack
http://mail.python.org/pipermail/python-dev/2012-January/115892.html
http://bugs.python.org/issue13703
http://python.org/download/releases/2.6.8/
http://python.org/download/releases/2.7.3/
http://python.org/download/releases/3.1.5/
http://python.org/download/releases/3.2.3/
https://bugzilla.redhat.com/show_bug.cgi?id=750555
openSUSE-SU-2020:0086
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html
CopyrightCopyright (C) 2021 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.