Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

openSUSE: 2024:0175-1 Critical: Python-aiohttp XSS Vulnerability Detection

opensuse
Calendar Grey January 19, 2024
Dist Opensuse Esm H88
Crucial security enhancement for python-aiohttp targeting injection vulnerabilities on openSUSE environments. Version elevated to 3.8.6.
This update for python-aiohttp fixes the following issues: Updated to version 3.8.6:

Description

This update for python-aiohttp fixes the following issues:

Updated to version 3.8.6:

* CVE-2023-49082: Fixed an HTTP header injection via a crafted method

(bsc#1217682).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.4

zypper in -t patch SUSE-2024-168=1

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2024-168=1

* Python 3 Module 15-SP5

zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2024-168=1

Package List

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)

* python311-aiohttp-debuginfo-3.8.6-150400.10.11.1

* python-aiohttp-debugsource-3.8.6-150400.10.11.1

* python311-aiohttp-3.8.6-150400.10.11.1

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* python311-aiohttp-debuginfo-3.8.6-150400.10.11.1

* python-aiohttp-debugsource-3.8.6-150400.10.11.1

* python311-aiohttp-3.8.6-150400.10.11.1

* Python 3 Module 15-SP5 (aarch64 ppc64le s390x x86_64)

* python311-aiohttp-debuginfo-3.8.6-150400.10.11.1

* python-aiohttp-debugsource-3.8.6-150400.10.11.1

* python311-aiohttp-3.8.6-150400.10.11.1

References

* bsc#1217682

## References:

* https://www.suse.com/security/cve/CVE-2023-49082.html

* https://bugzilla.suse.com/show_bug.cgi?id=1217682

Announcement ID: SUSE-SU-2024:0168-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here