[mod_python] [ANNOUNCE] Mod_python 3.1.4 and 2.7.11 (security)

Gregory (Grisha) Trubetskoy grisha at apache.org
Sat Feb 12 22:00:56 EST 2005

The Apache Software Foundation and The Apache HTTP Server Project are pleased 
to announce the release of versions 3.1.4 and 2.7.11 of mod_python.

This release addresses a vulnerability in mod_python's publisher handler 
whereby a carefully crafted URL would expose objects that should not be 
visible, leading to an information leak. The Common Vulnerabilities and 
Exposures project (http://cve.mitre.org/) has assigned the name CAN-2005-0088 
to this issue.

Users of the publisher handler are urged to upgrade as soon as possible.

There are no other changes or improvements from the previous version in
this release.

At this point the new version is only available as a source code archive.
Users of mod_python on Win32 platform can update their installation by simply 
replacing the publisher.py file with the latest version from the source code 

Mod_python is available for download from:


For more information about mod_python visit


Grisha Trubetskoy

More information about the Mod_python mailing list