It is currently Sat Jul 06, 2024 8:43 pm


All times are UTC - 5 hours [ DST ]



Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: Secunia PSI sez Python out of date (partha)
PostPosted: Thu Jun 14, 2012 1:39 am  (#1) 
Offline
GimpChat Member
User avatar

Joined: Apr 04, 2012
Posts: 51
Location: Hammond, IN, USA
GIMP Version: 2.8
Operating System: Windows
OS Version: Windows Vista Home Premium SP 2
GIMP Experience: Basic Level

List any relevant plug-ins or scripts:
Built-in Python interpreter 2.7.x



I'm using a "portable" build--a partha/samj build I'm certain--with python built in.

I use Secunia PSI to troubleshoot any insecure software I might be using, and it has flagged the python27.dll as insecure and is bugging me to update it to 2.7.3. Frankly, I really don't want to, but . . . :roll:

Is there any way to update python27.dll to the 2.7.3 standard without breaking GIMP?

Thanks,

Tony

_________________
Tony

mechatherium.deviantart.com


What did you expect? Shakespeare?


Share on Facebook Share on Twitter Share on Orkut Share on Digg Share on MySpace Share on Delicious Share on Technorati
Top
 Post subject: Re: Secunia PSI sez Python out of date (partha)
PostPosted: Thu Jun 14, 2012 7:18 am  (#2) 
Offline
GimpChat Member
User avatar

Joined: May 16, 2010
Posts: 14709
Location: USA
mechatherium wrote:
GIMP Version: 2.8
Operating System: Windows
OS Version: Windows Vista Home Premium SP 2
GIMP Experience: Basic Level

List any relevant plug-ins or scripts:
Built-in Python interpreter 2.7.x



I'm using a "portable" build--a partha/samj build I'm certain--with python built in.

I use Secunia PSI to troubleshoot any insecure software I might be using, and it has flagged the python27.dll as insecure and is bugging me to update it to 2.7.3. Frankly, I really don't want to, but . . . :roll:

Is there any way to update python27.dll to the 2.7.3 standard without breaking GIMP?

Thanks,

Tony


I don't believe so without Partha re compiling with a new version of Python.
The pythonw.exe and dll will not match otherwise.
Normally dll files will only work with executes compiled with it.

I think you can get around this by editing the pygimp.interp file and have it point to your installed version of Python 2.7.3 instead of the embedded one.Of course you will have to install Python 2.7.3 first.And pygtk and pycairo, and pyobject. So i don't recommend this.It would be too easy for something to get moved around and broken.

Can't you just turn that off for using Gimp?

_________________
Image
Edmund Burke nailed it when he said, "The only thing necessary for the triumph of evil is for good men to do nothing."


Top
 Post subject: Re: Secunia PSI sez Python out of date (partha)
PostPosted: Thu Jun 14, 2012 5:14 pm  (#3) 
Offline
GimpChat Member

Joined: Mar 14, 2011
Posts: 998
mechatherium wrote:
GIMP Version: 2.8
Operating System: Windows
OS Version: Windows Vista Home Premium SP 2
GIMP Experience: Basic Level

List any relevant plug-ins or scripts:
Built-in Python interpreter 2.7.x



I'm using a "portable" build--a partha/samj build I'm certain--with python built in.

I use Secunia PSI to troubleshoot any insecure software I might be using, and it has flagged the python27.dll as insecure and is bugging me to update it to 2.7.3. Frankly, I really don't want to, but . . . :roll:

Is there any way to update python27.dll to the 2.7.3 standard without breaking GIMP?

Thanks,

Tony

Tony,

The python version included in my builds is 2.7.3. If you start Gimp and open the python console you can see that for yourself.

I don't know anything about Secunia.


Top
 Post subject: Re: Secunia PSI sez Python out of date (partha)
PostPosted: Thu Jun 14, 2012 10:27 pm  (#4) 
Offline
Global Moderator
User avatar

Joined: Nov 16, 2011
Posts: 5128
Location: Metro Vancouver, BC
You can ignore the Secunia warning. It's probably referring the stand alone version of Python you were using with previous versions of Gimp. If you don't use Python for any other applications you can safely remove the stand alone version using the Control Panel.

_________________
Image
Gimp 2.8.18, Linux, median user
Gimp Chat Tutorials Index
Spirit Bear (Kermode)


Top
 Post subject: Re: Secunia PSI sez Python out of date (partha)
PostPosted: Fri Jun 15, 2012 8:54 am  (#5) 
Offline
GimpChat Member

Joined: Apr 12, 2010
Posts: 5870
No ANY reason to worry in your case:
only a malicious python script may use that vulnerability hole and should be a Gimp python script, because in the partha builds, python is included inside gimp, and so is on unusual path almost impossible to guess for who may target python vulnerabilities

So basically only a malicious gimp python script would have some chances to be loaded, and as far i know such script didn't exist, and i believe there are no much chances that somebody would never write one

Obviously if you was using python often and independently from gimp could be different, but in your case nothing to woryy :cool

_________________
My 3D Gallery on Deviantart http://photocomix2.deviantart.com/
Main gallery http://www.flickriver.com/photos/photocomix-mandala/
Mandala and simmetry http://www.flickriver.com/photos/photocomix_mandala/

Image

Mrs Wilbress


Top
 Post subject: Re: Secunia PSI sez Python out of date (partha)
PostPosted: Fri Jun 15, 2012 7:21 pm  (#6) 
Offline
GimpChat Member
User avatar

Joined: Apr 04, 2012
Posts: 51
Location: Hammond, IN, USA
Thanks, guys.

_________________
Tony

mechatherium.deviantart.com


What did you expect? Shakespeare?


Top
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC - 5 hours [ DST ]


   Similar Topics   Replies 
No new posts Attachment(s) the image proporates date missing all the time after saving it

3

No new posts Convert GIMP plugin from Python 2 to Python 3

4

No new posts Where Is Partha?

2

No new posts Samj, partha or org

3

No new posts Partha released portable Gimp 2.10.18

1



* Login  



Powered by phpBB3 © phpBB Group