RedHat: RHSA-2020-0197:01 Important: python-reportlab security update

    Date21 Jan 2020
    235
    Posted ByLinuxSecurity Advisories
    An update for python-reportlab is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA256
    
    =====================================================================
                       Red Hat Security Advisory
    
    Synopsis:          Important: python-reportlab security update
    Advisory ID:       RHSA-2020:0197-01
    Product:           Red Hat Enterprise Linux
    Advisory URL:      https://access.redhat.com/errata/RHSA-2020:0197
    Issue date:        2020-01-21
    CVE Names:         CVE-2019-17626 
    =====================================================================
    
    1. Summary:
    
    An update for python-reportlab is now available for Red Hat Enterprise
    Linux 6.
    
    Red Hat Product Security has rated this update as having a security impact
    of Important. A Common Vulnerability Scoring System (CVSS) base score,
    which gives a detailed severity rating, is available for each vulnerability
    from the CVE link(s) in the References section.
    
    2. Relevant releases/architectures:
    
    Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64
    Red Hat Enterprise Linux Desktop Optional (v. 6) - noarch
    Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, x86_64
    Red Hat Enterprise Linux Server Optional (v. 6) - noarch
    Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64
    Red Hat Enterprise Linux Workstation Optional (v. 6) - noarch
    
    3. Description:
    
    Python-reportlab is a library used for generation of PDF documents.
    
    Security Fix(es):
    
    * python-reportlab: code injection in colors.py allows attacker to execute
    code (CVE-2019-17626)
    
    For more details about the security issue(s), including the impact, a CVSS
    score, acknowledgments, and other related information, refer to the CVE
    page(s) listed in the References section.
    
    4. Solution:
    
    For details on how to apply this update, which includes the changes
    described in this advisory, refer to:
    
    https://access.redhat.com/articles/11258
    
    5. Bugs fixed (https://bugzilla.redhat.com/):
    
    1769661 - CVE-2019-17626 python-reportlab: code injection in colors.py allows attacker to execute code
    
    6. Package List:
    
    Red Hat Enterprise Linux Desktop (v. 6):
    
    Source:
    python-reportlab-2.3-3.el6_10.1.src.rpm
    
    i386:
    python-reportlab-2.3-3.el6_10.1.i686.rpm
    python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm
    
    x86_64:
    python-reportlab-2.3-3.el6_10.1.x86_64.rpm
    python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm
    
    Red Hat Enterprise Linux Desktop Optional (v. 6):
    
    noarch:
    python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm
    
    Red Hat Enterprise Linux Server (v. 6):
    
    Source:
    python-reportlab-2.3-3.el6_10.1.src.rpm
    
    i386:
    python-reportlab-2.3-3.el6_10.1.i686.rpm
    python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm
    
    ppc64:
    python-reportlab-2.3-3.el6_10.1.ppc64.rpm
    python-reportlab-debuginfo-2.3-3.el6_10.1.ppc64.rpm
    
    x86_64:
    python-reportlab-2.3-3.el6_10.1.x86_64.rpm
    python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm
    
    Red Hat Enterprise Linux Server Optional (v. 6):
    
    noarch:
    python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm
    
    Red Hat Enterprise Linux Workstation (v. 6):
    
    Source:
    python-reportlab-2.3-3.el6_10.1.src.rpm
    
    i386:
    python-reportlab-2.3-3.el6_10.1.i686.rpm
    python-reportlab-debuginfo-2.3-3.el6_10.1.i686.rpm
    
    x86_64:
    python-reportlab-2.3-3.el6_10.1.x86_64.rpm
    python-reportlab-debuginfo-2.3-3.el6_10.1.x86_64.rpm
    
    Red Hat Enterprise Linux Workstation Optional (v. 6):
    
    noarch:
    python-reportlab-docs-2.3-3.el6_10.1.noarch.rpm
    
    These packages are GPG signed by Red Hat for security.  Our key and
    details on how to verify the signature are available from
    https://access.redhat.com/security/team/key/
    
    7. References:
    
    https://access.redhat.com/security/cve/CVE-2019-17626
    https://access.redhat.com/security/updates/classification/#important
    
    8. Contact:
    
    The Red Hat security contact is . More contact
    details at https://access.redhat.com/security/team/contact/
    
    Copyright 2020 Red Hat, Inc.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1
    
    iQIVAwUBXidOqtzjgjWX9erEAQhMQxAAmGV4iZdo3naF5MbGI3thfqAM1mY2/lBI
    obLs+uFKnn+j2jRZUu/BD+Krvz5W9+WPVbWMwu97eB8wxYuG+d1sBl3f1ejlQeUY
    RmCkYPbdehmGilUk+WHpi8hv0BcQtbZhIz8Q6n+v45ZdbcFqUHTe/KW4tkDXtAau
    TMOQURE6H55GRlQEQA94+LMF5sjG9Kxy6IRwtna1X72yJENswSIrLUaY9weqAE9d
    qkWf/k45ieQVk2ATIzcg5+m8By5vPFlle86co4w+AWLFQZk6YEf8Xy0qtnv4j4i5
    53XLfyScpWBUPfOxaGSoSpLnLm4WWiRHdB9Z3cnfFVPP6kFXwY07yXDsIHONIaoo
    EQzFi8wZlFG4S62jVn+mwnSDxWuqu1xx6fv9qPBo96/hqEyn41esaPBXglXH7AnV
    n3rRJMnZdU1salqMZ8DT7rnkXuCI4nOT58uNSLVdJ1HCUHs6QdvOovA88Zj6r6pm
    d1O6MzxDfm/S32uWBquJWzm0bMCH/pAU1XqYsEcLvriUSxUwmsrrMa55GMwgeADK
    Vxas2kjEh3SG6fNsyFKfp6aa6DCwC7nZjSQ/bKR+lJEni17LmAk+rUnGqWR77uk5
    CXn2BY2a1JfSEqADs4f6F00+8WWls+9vy6NMCtwGqfka7Su675Yg4zXRXYygFp4z
    9XfBBJkDQLI=
    =fF16
    -----END PGP SIGNATURE-----
    
    --
    RHSA-announce mailing list
    This email address is being protected from spambots. You need JavaScript enabled to view it.
    https://www.redhat.com/mailman/listinfo/rhsa-announce
    

    LinuxSecurity Poll

    What do you think of the LinuxSecurity Privacy news articles?

    No answer selected. Please try again.
    Please select either existing option or enter your own, however not both.
    Please select minimum 0 answer(s) and maximum 3 answer(s).
    /main-polls/25-what-do-you-think-of-the-linuxsecurity-privacy-news-articles?task=poll.vote&format=json
    25
    radio
    [{"id":"90","title":"Love them!","votes":"48","type":"x","order":"1","pct":88.89,"resources":[]},{"id":"91","title":"I'm indifferent","votes":"4","type":"x","order":"2","pct":7.41,"resources":[]},{"id":"92","title":"Not interested in this topic","votes":"2","type":"x","order":"3","pct":3.7,"resources":[]}]["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"]["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"]350
    bottom200

    We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.