Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

SUSE Linux Enterprise python3: 2024:3470-1 important: resource concerns

suse
Calendar Grey September 27, 2024
Dist Suse Esm H88
Keep your systems secure by staying informed about vital Python3 security patches and updates on various SUSE Linux distributions and monitoring security alerts
* bsc#1227233 * bsc#1227378 * bsc#1227999 * bsc#1228780 * bsc#1229596

Summary

## This update for python3 fixes the following issues: * CVE-2024-6923: Fixed uncontrolled CPU resource consumption when in http.cookies module (bsc#1228780). * CVE-2024-5642: Fixed buffer overread when NPN is used and invalid values are sent to the OpenSSL API (bsc#1227233). * CVE-2024-7592: Fixed Email header injection due to unquoted newlines (bsc#1229596). * CVE-2024-6232: excessive backtracking when parsing tarfile headers leads to ReDoS. (bsc#1230227) Bug fixes: * %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999). * Stop using %%defattr, it seems to be breaking proper executable attributes on /usr/bin/ scripts (bsc#1227378). * Remove %suse_update_desktop_file macro as it is not useful any more. ## Patch Instructions:

References

* bsc#1227233

* bsc#1227378

* bsc#1227999

* bsc#1228780

* bsc#1229596

* bsc#1230227

Cross-

* CVE-2024-5642

* CVE-2024-6232

* CVE-2024-6923

* CVE-2024-7592

CVSS scores:

* CVE-2024-5642 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

* CVE-2024-6232 ( SUSE ): 8.9

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

* CVE-2024-6232 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-6232 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2024-7592 ( SUSE ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L

* CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP5

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:3470-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here