Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 39: FEDORA-2023-a04cc349e1 Critical: python-aiohttp Update

fedora
Calendar Grey January 8, 2024
Dist Fedora Esm H88
Make certain that Fedora 39's security patches are applied by refreshing python-aiohttp along with its related packages to address various CVEs.
Security fix for CVE-2023-49081, CVE-2023-49082

Summary

Python library to control a Logitech Media Server asynchronously.

Update Information:

Security fix for CVE-2023-49081, CVE-2023-49082. Update `python-aiohttp` to 3.9.1. Patch `python-pysqeezebox` and `python-wled` so they do not have an implicit dependency on `python-async-timeout` via `python-aiohttp`. libs/aiohttp/releases/tag/v3.9.0 libs/aiohttp/releases/tag/v3.9.1

Change Log

* Sat Dec 2 2023 Benjamin A. Beasley - 0.5.5-11 - Add explicit async-timeout dependency

References


[ 1 ] Bug #2252236 - TRIAGE CVE-2023-49081 python-aiohttp: aiohttp: HTTP request modification [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2252236 [ 2 ] Bug #2252249 - TRIAGE CVE-2023-49082 python-aiohttp: aiohttp: CRLF injection if user controls the HTTP method using aiohttp client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2252249 [ 3 ] Bug #2253439 - python-pysqueezebox: Please merge rawhide back to f39 and f38 https://bugzilla.redhat.com/show_bug.cgi?id=2253439 [ 4 ] Bug #2253440 - python-wled: Please merge rawhide back to f39 and f38 https://bugzilla.redhat.com/show_bug.cgi?id=2253440 [ 5 ] Bug #2254945 - deprecation warning: DeprecationWarning: datetime.datetime.utcnow() is deprecated and scheduled for removal https://bugzilla.redhat.com/show_bug.cgi?id=2254945

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a04cc349e1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-pysqueezebox
Product: Fedora 39
Version: 0.5.5
Release: 11.fc39
Summary: Python library to control Logitech Media Server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here