Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 38: Update FEDORA-2023-1f06098c71 critical: python-pysqueezebox DoS

fedora
Calendar Grey January 8, 2024
Dist Fedora Esm H88
Fedora 38 security patch for python-pysqueezebox addressing CVE-2023-49081 and CVE-2023-49082 has been released.
Security fix for CVE-2023-49081, CVE-2023-49082

Summary

Python library to control a Logitech Media Server asynchronously.

Update Information:

Security fix for CVE-2023-49081, CVE-2023-49082. Update `python-aiohttp` to 3.9.1. Patch `python-pysqeezebox` and `python-wled` so they do not have an implicit dependency on `python-async-timeout` via `python-aiohttp`. libs/aiohttp/releases/tag/v3.9.0 libs/aiohttp/releases/tag/v3.9.1

Change Log

* Sat Dec 2 2023 Benjamin A. Beasley - 0.5.5-11 - Add explicit async-timeout dependency * Fri Jul 21 2023 Fedora Release Engineering - 0.5.5-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jun 29 2023 Python Maint - 0.5.5-9 - Rebuilt for Python 3.12

References


[ 1 ] Bug #2252236 - TRIAGE CVE-2023-49081 python-aiohttp: aiohttp: HTTP request modification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2252236 [ 2 ] Bug #2252249 - TRIAGE CVE-2023-49082 python-aiohttp: aiohttp: CRLF injection if user controls the HTTP method using aiohttp client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2252249 [ 3 ] Bug #2253439 - python-pysqueezebox: Please merge rawhide back to f39 and f38 https://bugzilla.redhat.com/show_bug.cgi?id=2253439 [ 4 ] Bug #2253440 - python-wled: Please merge rawhide back to f39 and f38 https://bugzilla.redhat.com/show_bug.cgi?id=2253440 [ 5 ] Bug #2254945 - deprecation warning: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal https://bugzilla.redhat.com/show_bug.cgi?id=2254945

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1f06098c71' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-pysqueezebox
Product: Fedora 38
Version: 0.5.5
Release: 11.fc38
Summary: Python library to control Logitech Media Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here