Referenced CVEs:
CVE-2008-4864, CVE-2008-5031
Description:
===========================================================Ubuntu Security Notice USN-806-1 July 23, 2009python2.4, python2.5 vulnerabilitiesCVE-2008-4864, CVE-2008-5031===========================================================A security issue affects the following Ubuntu releases:Ubuntu 6.06 LTSUbuntu 8.04 LTSUbuntu 8.10This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 6.06 LTS: python2.4 2.4.3-0ubuntu6.3 python2.4-minimal 2.4.3-0ubuntu6.3Ubuntu 8.04 LTS: python2.4 2.4.5-1ubuntu4.2 python2.4-minimal 2.4.5-1ubuntu4.2 python2.5 2.5.2-2ubuntu6 python2.5-minimal 2.5.2-2ubuntu6Ubuntu 8.10: python2.4 2.4.5-5ubuntu1.1 python2.4-minimal 2.4.5-5ubuntu1.1After a standard system upgrade you need to reboot your computer toeffect the necessary changes.Details follow:It was discovered that Python incorrectly handled certain arguments in theimageop module. If an attacker were able to pass specially craftedarguments through the crop function, they could execute arbitrary code withuser privileges. For Python 2.5, this issue only affected Ubuntu 8.04 LTS.(CVE-2008-4864)Multiple integer overflows were discovered in Python's stringobject andunicodeobject expandtabs method. If an attacker were able to exploit theseflaws they could execute arbitrary code with user privileges or causePython applications to crash, leading to a denial of service.(CVE-2008-5031)
More...