security advisorymoderatedebian
Multiple security issues were discovered in Python, a high-level, interactive, object-oriented language: CVE-2024-0397 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5759-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff August 27, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python3.11 CVE ID : CVE-2024-0397 CVE-2024-4032 CVE-2024-8088 Multiple security issues were discovered in Python, a high-level, interactive, object-oriented language: CVE-2024-0397 A race condition in the ssl module was found when accessing CA certificates. CVE-2024-4032 The ipaddress module contained incorrect information whether some ipv4 and ipv6 address ranges are designated as globally reachable or private. CVE-2024-8088 Incorrect handling of path names in the zipfile module could result in an infinite loop when processing a zip archive (resulting in denial of service) For the stable distribution (bookworm), these problems have been fixed in version 3.11.2-6+deb12u3. We recommend that you upgrade your python3.11 packages. For the detailed security status of python3.11 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python3.11 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities found in Python 3.11 lead to race conditions, denial of service, and inaccurate data on memory addresses.. Debian Security, DoS Attacks, SSL Vulnerabilities, Python Security. . LinuxSecurity.com Team
Aug 27, 2024
Debian