Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE Linux 12-SP3: 2018:2696-1 Moderate: Python3 Denial Of Service

suse
Calendar Grey September 12, 2018
Dist Suse Esm H88
SUSE Security Update for python3: two updates addressing moderate concerns tied to denial of service vulnerabilities.
An update that solves two vulnerabilities and has two fixes is now available

Summary

This update for python3 provides the following fixes: These security issues were fixed: - CVE-2018-1061: Prevent catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could have used this flaw to cause denial of service (bsc#1088004). - CVE-2018-1060: Prevent catastrophic backtracking in pop3lib's apop() method. An attacker could have used this flaw to cause denial of service (bsc#1088009). These non-security issues were fixed: - Sort files and directories when creating tarfile archives so that they are created in a more predictable way. (bsc#1086001) - Add -fwrapv to OPTS (bsc#1107030) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1086001 #1088004 #1088009 #1107030

Cross- CVE-2018-1060 CVE-2018-1061

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Module for Web Scripting 12

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2018-1060.html

https://www.suse.com/security/cve/CVE-2018-1061.html

https://bugzilla.suse.com/1086001

https://bugzilla.suse.com/1088004

https://bugzilla.suse.com/1088009

https://bugzilla.suse.com/1107030

Announcement ID: SUSE-SU-2018:2696-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here