Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2021:4104-1 Moderate: python3 Information Disclosure and ReDoS

suse
Calendar Grey December 16, 2021
Dist Suse Esm H88
SUSE has rolled out a new update addressing critical python3 vulnerabilities that pose risks of information leaks and ReDoS, strengthening overall system security.
An update that solves three vulnerabilities and has four fixes is now available

Summary

This update for python3 fixes the following issues: - CVE-2021-3426: Fixed information disclosure via pydoc (bsc#1183374). - CVE-2021-3733: Fixed infinitely reading potential HTTP headers after a 100 Continue status response from the server (bsc#1189241). - CVE-2021-3737: Fixed ReDoS in urllib.request (bsc#1189287). - We do not require python-rpm-macros package (bsc#1180125). - Use versioned python-Sphinx to avoid dependency on other version of Python (bsc#1183858). - Stop providing "python" symbol, which means python2 currently (bsc#1185588). - Modify Lib/ensurepip/__init__.py to contain the same version numbers as are in reality the ones in the bundled wheels (bsc#1187668). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1180125 #1183374 #1183858 #1185588 #1187668

#1189241 #1189287

Cross- CVE-2021-3426 CVE-2021-3733 CVE-2021-3737

CVSS scores:

CVE-2021-3426 (NVD) : 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2021-3426 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2021-3733 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2021-3737 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Module for Development Tools 15-SP3

SUSE Linux Enterprise Module for Basesystem 15-SP3

https://www.suse.com/security/cve/CVE-2021-3426.html

https://www.suse.com/security/cve/CVE-2021-3733.html

https://www.suse.com/security/cve/CVE-2021-3737.html

https://bugzilla.suse.com/1180125

Announcement ID: SUSE-SU-2021:4104-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here