python: Cookie domain check returns incorrect results * python: email.utils.parseaddr wrongly parses email addresses SL7 x86_64 python3-libs-3.6.8-13.el7.i686.rpm python3-3.6.8-13.el7.x86_64.rpm python3-libs-3.6.8-13.el7.x86_64.rpm python3-debuginfo-3.6.8-13.el7.i686.rpm python3-debuginfo-3.6.8-13.el7.x86_64.rpm python3-3.6.8-13.el7.i686.rpm python3-debug-3.6 [More...]. Synopsis: Moderate: python3 security update Advisory ID: SLSA-2020:1132-1 Issue Date: 2020-04-07 CVE Numbers: CVE-2018-20852 CVE-2019-16056 -- * python: Cookie domain check returns incorrect results * python: email.utils.parseaddr wrongly parses email addresses -- SL7 x86_64 python3-libs-3.6.8-13.el7.i686.rpm python3-3.6.8-13.el7.x86_64.rpm python3-libs-3.6.8-13.el7.x86_64.rpm python3-debuginfo-3.6.8-13.el7.i686.rpm python3-debuginfo-3.6.8-13.el7.x86_64.rpm python3-3.6.8-13.el7.i686.rpm python3-debug-3.6.8-13.el7.i686.rpm python3-debug-3.6.8-13.el7.x86_64.rpm python3-devel-3.6.8-13.el7.i686.rpm python3-devel-3.6.8-13.el7.x86_64.rpm python3-idle-3.6.8-13.el7.i686.rpm python3-idle-3.6.8-13.el7.x86_64.rpm python3-test-3.6.8-13.el7.i686.rpm python3-test-3.6.8-13.el7.x86_64.rpm python3-tkinter-3.6.8-13.el7.i686.rpm python3-tkinter-3.6.8-13.el7.x86_64.rpm - Scientific Linux Development Team . A careful patch for python3 has been released, rectifying issues with faulty cookie checks and improper email formatting in Scientific Linux.. python update, cookie validation, email parsing. . Severity: Important. LinuxSecurity.com Team
It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read. . Package : libsoup2.4 Version : 2.48.0-1+deb8u2 CVE ID : CVE-2018-12910 It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read. For Debian 8 "Jessie", these problems have been fixed in version 2.48.0-1+deb8u2. We recommend that you upgrade your libsoup2.4 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update libsoup2.4 to address out-of-bounds memory access vulnerabilities in Debian 8 Jessie. Securely correct cookie verification problems.. libsoup2.4, Debian Jessie, security update, out-of-bounds, memory read. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.