Release date:
Updated on: 2012-03-30
Affected Systems:
Debian Linux 6.0 x
Python trytond 2.2.1
Unaffected system:
Python trytond 2.2.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52804
Cve id: CVE-2012-0215
Python is an object-oriented, literal translation computer programming language and a powerful general-purpose language.
When the trytond module verifies the permission of the "many2133" field in the access relationship model, Python has a security vulnerability in implementation. You can add users to other groups and obtain other permissions.
<* Source: vendor
Link: http://secunia.com/advisories/48635/
Http://news.tryton.org/2012/03/security-releases-for-all-supported.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Python
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Www.python.org