Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

openSUSE: 2022:10183-1 Moderate: Pyenv Security Fix for DoS

opensuse
Calendar Grey October 31, 2022
Dist Opensuse Esm H88
Patch released for pyenv on openSUSE, resolving CVE-2022-35861 rated as moderate risk. Ensure you update immediately!
An update that fixes one vulnerability is now available

Description

This update for pyenv fixes the following issues:

Update to 2.3.5

- Add CPython 3.10.7 by @edgarrmondragon in #2454

- Docs: update Fish PATH update by @gregorias in #2449

- Add CPython 3.7.14, 3.8.14 and 3.9.14 by @edgarrmondragon in #2456

- Update miniconda3-3.9-4.12.0 by @Tsuki in #2460

- Add CPython 3.11.0rc2 by @ViktorHaag in #2459

- Add patches for 3.7.14 to support Apple Silicon by @samdoran in #2463

- Add ability to easily skip all use of Homebrew by @samdoran in #2464

- Drop Travis integration by @sobolevn in #2468

- Build CPython 3.12+ with --with-dsymutil in MacOS by @native-api in #2471

- Add Pyston 2.3.5 by @scop in #2476 Full Changelog:

https://github.com/pyenv/pyenv/compare/v2.3.4...v2.3.5

Update to 2.3.4

- Add CPython 3.11.0rc1 by @edgarrmondragon in #2434

- Add support for multiple versions in pyenv uninstall by @hardikpnsp in

#2432

- Add micropython 1.18 and 1.19.1 by @dmitriy-serdyuk in #2443

- CI:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2022-10183=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

pyenv-2.3.5-bp154.2.3.1

- openSUSE Backports SLE-15-SP4 (noarch):

pyenv-bash-completion-2.3.5-bp154.2.3.1

pyenv-fish-completion-2.3.5-bp154.2.3.1

pyenv-zsh-completion-2.3.5-bp154.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-35861.html

https://bugzilla.suse.com/1201582

Announcement ID: openSUSE-SU-2022:10183-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here