This update for python3 to version 3.6.10 fixes the following issues:
- CVE-2017-18207: Fixed a denial of service in Wave_read._read_fmt_chunk()
(bsc#1083507).
- CVE-2019-16056: Fixed an issue where email parsing could fail for
multiple @ (bsc#1149955).
- CVE-2019-15903: Fixed a heap-based buffer over-read in libexpat
(bsc#1149429).
This update was imported from the SUSE:SLE-15:Update update project.
Patch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-86=1
- openSUSE Leap 15.1 (i586 x86_64):
libpython3_6m1_0-3.6.10-lp151.6.7.1
libpython3_6m1_0-debuginfo-3.6.10-lp151.6.7.1
python3-3.6.10-lp151.6.7.1
python3-base-3.6.10-lp151.6.7.1
python3-base-debuginfo-3.6.10-lp151.6.7.1
python3-base-debugsource-3.6.10-lp151.6.7.1
python3-curses-3.6.10-lp151.6.7.1
python3-curses-debuginfo-3.6.10-lp151.6.7.1
python3-dbm-3.6.10-lp151.6.7.1
python3-dbm-debuginfo-3.6.10-lp151.6.7.1
python3-debuginfo-3.6.10-lp151.6.7.1
python3-debugsource-3.6.10-lp151.6.7.1
python3-devel-3.6.10-lp151.6.7.1
python3-devel-debuginfo-3.6.10-lp151.6.7.1
python3-idle-3.6.10-lp151.6.7.1
python3-testsuite-3.6.10-lp151.6.7.1
python3-testsuite-debuginfo-3.6.10-lp151.6.7.1
python3-tk-3.6.10-lp151.6.7.1
python3-tk-debuginfo-3.6.10-lp151.6.7.1
python3-tools-3.6.10-lp151.6.7.1
- openSUSE Leap 15.1 (x86_64):
libpython3_6m1_0-32bit-3.6.10-lp151.6.7.1
libpython3_6m1_0-32bit-debuginfo-3.6.10-lp151.6.7.1
python3-32bit-3.6.10-lp151.6.7.1
python3-32bit-debuginfo-3.6.10-lp151.6.7.1
python3-base-32bit-3.6.10-lp151.6.7.1
pyth...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2011-3389.html
https://www.suse.com/security/cve/CVE-2011-4944.html
https://www.suse.com/security/cve/CVE-2012-0845.html
https://www.suse.com/security/cve/CVE-2012-1150.html
https://www.suse.com/security/cve/CVE-2013-1752.html
https://www.suse.com/security/cve/CVE-2013-4238.html
https://www.suse.com/security/cve/CVE-2014-2667.html
https://www.suse.com/security/cve/CVE-2014-4650.html
https://www.suse.com/security/cve/CVE-2016-0772.html
https://www.suse.com/security/cve/CVE-2016-1000110.html
https://www.suse.com/security/cve/CVE-2016-5636.html
https://www.suse.com/security/cve/CVE-2016-5699.html
https://www.suse.com/security/cve/CVE-2017-18207.html
https://https://www.suse.com/security/cve/CVE-2018-1000802.html
https://www.suse.com/security/cve/CVE-2018-1060.html
https://www.suse.com/security/cve/CVE-2018-1061.html
https://www.suse.com/security/cve/CVE-2018-14647.html
https://www.suse.com/security/cve/CVE-2018-20406.html
https://www.suse.com/security/cve/CVE-2018-2085...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.