[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2541-1 beaker -- information disclosure

ID: oval:org.secpod.oval:def:600879Date: (C)2012-09-13   (M)2022-10-10
Class: PATCHFamily: unix




It was discovered that Beaker, a cache and session library for Python, when using the python-crypto backend, is vulnerable to information disclosure due to a cryptographic weakness related to the use of the AES cipher in ECB mode. Systems that have the python-pycryptopp package should not be vulnerable, as this backend is preferred over python-crypto. After applying this update, existing sessions will be invalidated.

Platform:
Debian 6.0
Product:
python-beaker
python3-beaker
Reference:
DSA-2541-1
CVE-2012-3458
CVE    1
CVE-2012-3458
CPE    3
cpe:/a:python:python3-beaker
cpe:/o:debian:debian_linux:6.0
cpe:/a:python:python-beaker

© SecPod Technologies