Fix for CVE-2023-24329. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-309cadedc6 2023-06-08 01:59:06.605307 --------------------------------------------------------------------------------Name : python3.10 Product : Fedora 37 Version : 3.10.11 Release : 2.fc37 URL : https://www.python.org/ Summary : Version 3.10 of the Python interpreter Description : Python 3.10 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.10 package provides the "python3.10" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.10-libs package, which should be installed automatically along with python3.10. The remaining parts of the Python standard library are broken out into the python3.10-tkinter and python3.10-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.10-docs package. Packages containing additional libraries for Python are generally named with the "python3.10-" prefix. --------------------------------------------------------------------------------Update Information: Fix for CVE-2023-24329 --------------------------------------------------------------------------------ChangeLog: * Mon May 29 2023 Charalampos Stratakis - 3.10.11-2 - Fix for CVE-2023-24329 Resolves: rhbz#2174010 --------------------------------------------------------------------------------References: [ 1 ] Bug #2174010 - CVE-2023-24329 python3.10: python: urllib.parse url blocklisting bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2174010 --------------------------------------------------------------------------------This update can be installed with the"dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-309cadedc6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.3/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:774-1 Container Tags : suse/sle-micro/5.3/toolbox:12.1 , suse/sle-micro/5.3/toolbox:12.1-5.2.95 , suse/sle-micro/5.3/toolbox:latest Container Release : 5.2.95 Severity : important Type : security References : 1203355 1208471 CVE-2023-24329 ----------------------------------------------------------------- The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:868-1 Released: Wed Mar 22 09:41:01 2023 Summary: Security update for python3 Type: security Severity: important References: 1203355,1208471,CVE-2023-24329 This update for python3 fixes the following issues: - CVE-2023-24329: Fixed a blocklist bypass via the urllib.parse component when supplying a URL that starts with blank characters (bsc#1208471). The following non-security bug was fixed: - Eliminate unnecessary and dangerous calls to PyThread_exit_thread() (bsc#1203355). The following package changes have been done: - libpython3_6m1_0-3.6.15-150300.10.45.1 updated - python3-base-3.6.15-150300.10.45.1 updated . Important security enhancements in the SUSE toolbox container address various vulnerabilities, with a significant focus on a critical issue related to python3.. SUSE Toolbox Update, Python3 Security Fix, Container Vulnerability Management. . Severity: Important. LinuxSecurity.com Team
The container suse/389-ds was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/389-ds ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:767-1 Container Tags : suse/389-ds:2.0 , suse/389-ds:2.0-20.7 , suse/389-ds:latest Container Release : 20.7 Severity : important Type : security References : 1203355 1208471 CVE-2023-24329 ----------------------------------------------------------------- The container suse/389-ds was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:868-1 Released: Wed Mar 22 09:41:01 2023 Summary: Security update for python3 Type: security Severity: important References: 1203355,1208471,CVE-2023-24329 This update for python3 fixes the following issues: - CVE-2023-24329: Fixed a blocklist bypass via the urllib.parse component when supplying a URL that starts with blank characters (bsc#1208471). The following non-security bug was fixed: - Eliminate unnecessary and dangerous calls to PyThread_exit_thread() (bsc#1203355). The following package changes have been done: - python3-base-3.6.15-150300.10.45.1 updated - libpython3_6m1_0-3.6.15-150300.10.45.1 updated . The SUSE Software Security Bulletin provides critical patches for suse/389-ds and python3, focusing on vulnerabilities that need attention.. SUSE Security Update, SUSE Container Advisory, suse/389-ds Update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.