mod_python: Publisher Handler vulnerability — GLSA 200502-14 mod_python contains a vulnerability in the Publisher Handler potentially leading to information disclosure. Affected packages Package www-apache/mod_python on all architectures Affected versions < 3.1.3-r1 Unaffected versions >= 3.1.3-r1 revision >= 2.7.11 Background mod_python is an Apache module that embeds the Python interpreter within the server allowing Python-based web-applications to be created. Description Graham Dumpleton discovered a vulnerability in mod_python's Publisher Handler. Impact By requesting a specially crafted URL for a published module page, an attacker could obtain information about restricted variables. Workaround There is no known workaround at this time. Resolution All mod_python users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose www-apache/mod_python References CAN-2005-0088