Name | CVE-2005-0089 |
Description | The SimpleXMLRPCServer library module in Python 2.2, 2.3 before 2.3.5, and 2.4, when used by XML-RPC servers that use the register_instance method to register an object without a _dispatch method, allows remote attackers to read or modify globals of the associated module, and possibly execute arbitrary code, via dotted attributes. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DSA-666-1 |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
python2.2 | source | woody | 2.2.1-4.7 | DSA-666-1 | ||
python2.2 | source | (unstable) | 2.2.3-14 | |||
python2.3 | source | (unstable) | 2.3.4+2.3.5c1-2 | |||
python2.4 | source | (unstable) | 2.4-5 |