SB2016090103 - Amazon Linux AMI update for python34, python27, python26
Published: September 1, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Open redirect (CVE-ID: CVE-2016-1000110)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
Remediation
Install update from vendor's website.