Vuln in Python bundled with Windows release

Bug #1740727 reported by Chris Pavlina
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
KiCad
Fix Released
High
Nick Østergaard

Bug Description

We're shipping Python 2.7.13 with the Windows release, which is subject to CVE-2017-1000158 (integer overflow resulting in possible ACE, [1]). This has been fixed in 2.7.14 (see "bpo-30657" in [2]) so we should upgrade to this before 5.0.

[1] https://nvd.nist.gov/vuln/detail/CVE-2017-1000158
[2] https://raw.githubusercontent.com/python/cpython/84471935ed2f62b8c5758fd544c7d37076fe0fa5/Misc/NEWS

Tags: python windows
Revision history for this message
Chris Pavlina (pavlina-chris) wrote :

Personally, I'd do an interim minor release 4.0.8, as it's fairly serious to be installing Pythons on users' machines with ACE vulns and swapping out the Python version should be pretty trivial.

Revision history for this message
Wayne Stambaugh (stambaughw) wrote : Re: [Bug 1740727] Re: Vuln in Python bundled with Windows release

Wouldn't this be a bump in the package version i.e. 4.0.7-2? Given that
there are no plans to change the kicad stable 4 source, using version
4.0.8 will be misleading at best.

On 1/1/2018 12:34 AM, Chris Pavlina wrote:
> Personally, I'd do an interim minor release 4.0.8, as it's fairly
> serious to be installing Pythons on users' machines with ACE vulns and
> swapping out the Python version should be pretty trivial.
>

Revision history for this message
Chris Pavlina (pavlina-chris) wrote :

Well sure - I don't know the details of the version numbering policy wrt external things like this, call it whatever you want.

Jon Evans (craftyjon)
Changed in kicad:
milestone: none → 5.0.0-rc1
Changed in kicad:
milestone: 5.0.0-rc1 → 5.0.0-rc2
Revision history for this message
Nick Østergaard (nickoe) wrote :

Should be fixed in the next nightlies.

Changed in kicad:
status: New → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.