Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Fedora 32: 2020-dfb11916cc Moderate: mingw-python3 DoS Issues

fedora
Calendar Grey July 22, 2020
Dist Fedora Esm H88
Fedora 32 released a mingw-python3 refresh to address CVE-2019-20907 and CVE-2020-14422 security vulnerabilities, safeguarding users from exploitation risks
Backport patch for CVE-2019-20907

Summary

MinGW Windows python3 library.

Backport patch for CVE-2019-20907. ---- Update to 3.8.3, backport patch for

CVE-2020-14422.

* Tue Jul 14 2020 Sandro Mani - 3.8.3-3

- Backport patch for CVE-2019-20907

* Mon Jul 13 2020 Sandro Mani - 3.8.3-2

- Backport patch for CVE-2020-14422

* Sun May 17 2020 Sandro Mani - 3.8.3-1

- Update to 3.8.3

* Mon Mar 2 2020 Sandro Mani - 3.8.2-1

- Update to 3.8.2

[ 1 ] Bug #1854936 - CVE-2020-14422 mingw-python3: python: DoS via inefficiency in IPv{4,6}Interface classes [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1854936

[ 2 ] Bug #1856489 - CVE-2019-20907 mingw-python3: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1856489

su -c 'dnf upgrade --advisory FEDORA-2020-dfb11916cc' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Product: Fedora 32
Version: 3.8.3
Release: 3.fc32
Summary: MinGW Windows python3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here