Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia 7: MGASA-2019-0318 moderate: Python Email Parsing & XSS Issues

mageia
Calendar Grey November 7, 2019
Dist Mageia Esm H88
Recently enhanced Python libraries addressed vulnerabilities concerning email interpretation and XSS threats, deemed essential for Mageia.
Updated python and python3 packages fix security vulnerabilities: It was discovered that Python incorrectly parsed certain email addresses

Summary

Updated python and python3 packages fix security vulnerabilities: It was discovered that Python incorrectly parsed certain email addresses. A remote attacker could possibly use this issue to trick Python applications into accepting email addresses that should be denied (CVE-2019-16056).
It was discovered that the Python documentation XML-RPC server incorrectly handled certain fields. A remote attacker could use this issue to execute a cross-site scripting (XSS) attack (CVE-2019-16935).

References

- https://bugs.mageia.org/show_bug.cgi?id=25641

- https://ubuntu.com/security/notices/USN-4151-1

- https://www.cve.org/CVERecord?id=CVE-2019-16056

- https://www.cve.org/CVERecord?id=CVE-2019-16935

Resolution

SRPMS

- 7/core/python-2.7.17-1.1.mga7

- 7/core/python3-3.7.5-1.mga7

Publication date: 07 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0318.html
Type: security
CVE: CVE-2019-16056, CVE-2019-16935

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here