Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

SUSE: 2022:2291-1 Important: Python310 Command Injection Fix

suse
Calendar Grey July 6, 2022
Dist Suse Esm H88
A vital security update for Python 3.10 is out to address a command injection vulnerability. Users must upgrade to minimize risks from this issue.
An update that fixes one vulnerability is now available

Summary

This update for python310 fixes the following issues: - CVE-2015-20107: avoid command injection in the mailcap module (bsc#1198511). - Update to 3.10.5: - Core and Builtins - gh-93418: Fixed an assert where an f-string has an equal sign '=' following an expression, but there's no trailing brace. For example, f"{i=". - gh-91924: Fix __ltrace__ debug feature if the stdout encoding is not UTF-8. Patch by Victor Stinner. - gh-93061: Backward jumps after async for loops are no longer given dubious line numbers. - gh-93065: Fix contextvars HAMT implementation to handle iteration over deep trees. - The bug was discovered and fixed by Eli Libman. See MagicStack/immutables#84 for more details. - gh-92311: Fixed a bug where setting frame.f_lineno to jump over a list comprehension could misbehave or crash.

References

#1198511

Cross- CVE-2015-20107

CVSS scores:

CVE-2015-20107 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2015-20107 (SUSE): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Affected Products:

SUSE Linux Enterprise Module for Python3 15-SP4

openSUSE Leap 15.4

https://www.suse.com/security/cve/CVE-2015-20107.html

https://bugzilla.suse.com/1198511

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2291-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here