Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Several security issues were fixed in python2.7. ========================================================================== Ubuntu Security Notice USN-8018-3 March 19, 2026 python2.7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in python2.7 Software Description: - python2.7: An interactive high-level object-oriented language Details: USN-8018-1 fixed CVE-2025-12084, CVE-2025-15282, CVE-2026-0672, CVE-2026-0865 for python3. This update provides the corresponding updates for python2.7. Original advisory details: Denis Ledoux discovered that Python incorrectly parsed email message headers. An attacker could possibly use this issue to inject arbitrary headers into email messages. This issue only affected python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and python3.14 packages. (CVE-2025-11468) Jacob Walls, Shai Berger, and Natalia Bidart discovered that Python inefficiently parsed XML input with quadratic complexity. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-12084) It was discovered that Python incorrectly parsed malicious plist files. An attacker could possibly use this issue to cause Python to use excessive resources, leading to a denial of service. This issue only affected python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12, python3.13, and python3.14 packages. (CVE-2025-13837) Omar Hasan discovered that Python incorrectly parsed URL mediatypes. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2025-15282) Omar Hasan discovered that Python incorrectly parsed malicious IMAP inputs. An attacker could possibly use this issue to inject arbitrary IMAP commands.(CVE-2025-15366) Omar Hasan discovered that Python incorrectly parsed malicious POP3 inputs. An attacker could possibly use this issue to inject arbitrary POP3 commands. (CVE-2025-15367) Omar Hasan discovered that Python incorrectly parsed malicious HTTP cookie headers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-0672) Omar Hasan discovered that Python incorrectly parsed malicious HTTP header names and values. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-0865) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libpython2.7 2.7.18-13ubuntu1.5+esm8 Available with Ubuntu Pro python2.7 2.7.18-13ubuntu1.5+esm8 Available with Ubuntu Pro Ubuntu 20.04 LTS libpython2.7 2.7.18-1~20.04.7+esm9 Available with Ubuntu Pro python2.7 2.7.18-1~20.04.7+esm9 Available with Ubuntu Pro Ubuntu 18.04 LTS libpython2.7 2.7.17-1~18.04ubuntu1.13+esm14 Available with Ubuntu Pro python2.7 2.7.17-1~18.04ubuntu1.13+esm14 Available with Ubuntu Pro Ubuntu 16.04 LTS libpython2.7 2.7.12-1ubuntu0~16.04.18+esm19 Available with Ubuntu Pro python2.7 2.7.12-1ubuntu0~16.04.18+esm19 Available with Ubuntu Pro Ubuntu 14.04 LTS libpython2.7 2.7.6-8ubuntu0.6+esm29 Available with Ubuntu Pro python2.7 2.7.6-8ubuntu0.6+esm29 Available with Ubuntu Pro In general, a standard system update will make all the necessarychanges. References: https://ubuntu.com/security/notices/USN-8018-3 https://ubuntu.com/security/notices/USN-8018-2 https://ubuntu.com/security/notices/USN-8018-1 CVE-2025-12084, CVE-2025-15282, CVE-2026-0672, CVE-2026-0865 . Critical security updates for Python 2.7 in multiple Ubuntu releases to fix denial of service and HTTP header injection issues.. Python 2.7 Security Ubuntu Updates, Ubuntu 22.04 LTS Security Notices, Python Denial of Service Threats. . Severity: Critical. LinuxSecurity.com Team
Security fixes for CVE-2026-1299, CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f17f6e94ca 2026-03-07 02:24:06.258363+00:00 -------------------------------------------------------------------------------- Name : python3.11 Product : Fedora 43 Version : 3.11.14 Release : 5.fc43 URL : https://www.python.org/ Summary : Version 3.11 of the Python interpreter Description : Python 3.11 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.11 package provides the "python3.11" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.11-libs package, which should be installed automatically along with python3.11. The remaining parts of the Python standard library are broken out into the python3.11-tkinter and python3.11-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.11-docs package. Packages containing additional libraries for Python are generally named with the "python3.11-" prefix. -------------------------------------------------------------------------------- Update Information: Security fixes for CVE-2026-1299, CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367 -------------------------------------------------------------------------------- ChangeLog: * Mon Feb 9 2026 Tom\u0161 Hrn\u010diar - 3.11.14-5 - Security fixes for CVE-2026-0865, CVE-2025-15366 and CVE-2025-15367 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2431626 - CVE-2025-15366 python3.11: IMAP command injection in user-controlled commands [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431626 [ 2 ] Bug #2431650 - CVE-2025-15367 python3.11: POP3 command injection in user-controlled commands [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431650 [ 3 ] Bug #2431826 - CVE-2026-0865 python3.11: wsgiref.headers.Headers allows header newline injection in Python [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431826 [ 4 ] Bug #2433826 - CVE-2026-1299 python3.11: email header injection due to unquoted newlines [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2433826 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f17f6e94ca' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Recent security advisory for Fedora 43 sets critical fixes for multiple CVEs in python3.11, emphasizing command injection issues.. Fedora 43 Updates, Python 3.11 Security, Command Injection Fixes, Python CVEs. . Severity: Important. LinuxSecurity.com Team
An update that solves three vulnerabilities and has three security fixes can now be installed.. # Security update for python311 Announcement ID: SUSE-SU-2025:02089-1 Release Date: 2025-06-24T12:08:27Z Rating: important References: * bsc#1225660 * bsc#1226447 * bsc#1226448 * bsc#1227378 * bsc#1227999 * bsc#1228780 Cross-References: * CVE-2024-0397 * CVE-2024-4032 * CVE-2024-6923 CVSS scores: * CVE-2024-0397 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2024-0397 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-4032 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-6923 ( NVD ): 5.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities and has three security fixes can now be installed. ## Description: This update for python311 fixes the following issues: Security issues fixed: * CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-0397: Fixed memory race condition in ssl.SSLContext certificate store methods (bsc#1226447) * CVE-2024-4032: Fixed incorrect IPv4 and IPv6 private ranges (bsc#1226448) Non-security issues fixed: * Fixed executable bits for /usr/bin/idle* (bsc#1227378). * Improve python reproducible builds (bsc#1227999) * Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660) * %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_updateor "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2089=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2089=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2025-2089=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * python311-curses-debuginfo-3.11.9-150600.3.3.1 * python311-testsuite-3.11.9-150600.3.3.1 * python311-testsuite-debuginfo-3.11.9-150600.3.3.1 * python311-doc-3.11.9-150600.3.3.1 * python311-curses-3.11.9-150600.3.3.1 * python311-doc-devhelp-3.11.9-150600.3.3.1 * python311-base-3.11.9-150600.3.3.1 * python311-dbm-debuginfo-3.11.9-150600.3.3.1 * python311-3.11.9-150600.3.3.1 * libpython3_11-1_0-debuginfo-3.11.9-150600.3.3.1 * python311-tk-debuginfo-3.11.9-150600.3.3.1 * python311-dbm-3.11.9-150600.3.3.1 * python311-debuginfo-3.11.9-150600.3.3.1 * python311-devel-3.11.9-150600.3.3.1 * python311-debugsource-3.11.9-150600.3.3.1 * python311-base-debuginfo-3.11.9-150600.3.3.1 * python311-tools-3.11.9-150600.3.3.1 * python311-idle-3.11.9-150600.3.3.1 * python311-tk-3.11.9-150600.3.3.1 * openSUSE Leap 15.6 (x86_64) * libpython3_11-1_0-32bit-debuginfo-3.11.9-150600.3.3.1 * python311-32bit-debuginfo-3.11.9-150600.3.3.1 * python311-base-32bit-debuginfo-3.11.9-150600.3.3.1 * python311-base-32bit-3.11.9-150600.3.3.1 * libpython3_11-1_0-32bit-3.11.9-150600.3.3.1 * python311-32bit-3.11.9-150600.3.3.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * libpython3_11-1_0-debuginfo-3.11.9-150600.3.3.1 * python311-base-debuginfo-3.11.9-150600.3.3.1 * python311-base-3.11.9-150600.3.3.1 *Python 3 Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python311-3.11.9-150600.3.3.1 * python311-debuginfo-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * python311-devel-3.11.9-150600.3.3.1 * python311-debugsource-3.11.9-150600.3.3.1 * python311-curses-debuginfo-3.11.9-150600.3.3.1 * python311-tk-debuginfo-3.11.9-150600.3.3.1 * python311-curses-3.11.9-150600.3.3.1 * python311-tools-3.11.9-150600.3.3.1 * python311-idle-3.11.9-150600.3.3.1 * python311-dbm-debuginfo-3.11.9-150600.3.3.1 * python311-dbm-3.11.9-150600.3.3.1 * python311-tk-3.11.9-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0397.html * https://www.suse.com/security/cve/CVE-2024-4032.html * https://www.suse.com/security/cve/CVE-2024-6923.html * https://bugzilla.suse.com/show_bug.cgi?id=1225660 * https://bugzilla.suse.com/show_bug.cgi?id=1226447 * https://bugzilla.suse.com/show_bug.cgi?id=1226448 * https://bugzilla.suse.com/show_bug.cgi?id=1227378 * https://bugzilla.suse.com/show_bug.cgi?id=1227999 * https://bugzilla.suse.com/show_bug.cgi?id=1228780 . An important Fedora security patch addresses multiple vulnerabilities in python312, focusing on command injection and potential buffer overflow issues.. openSUSE python security important advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1225660 * bsc#1226447 * bsc#1226448 * bsc#1227378 * bsc#1227999 . # Security update for python311 Announcement ID: SUSE-SU-2025:02089-1 Release Date: 2025-06-24T12:08:27Z Rating: important References: * bsc#1225660 * bsc#1226447 * bsc#1226448 * bsc#1227378 * bsc#1227999 * bsc#1228780 Cross-References: * CVE-2024-0397 * CVE-2024-4032 * CVE-2024-6923 CVSS scores: * CVE-2024-0397 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2024-0397 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-4032 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-6923 ( NVD ): 5.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities and has three security fixes can now be installed. ## Description: This update for python311 fixes the following issues: Security issues fixed: * CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-0397: Fixed memory race condition in ssl.SSLContext certificate store methods (bsc#1226447) * CVE-2024-4032: Fixed incorrect IPv4 and IPv6 private ranges (bsc#1226448) Non-security issues fixed: * Fixed executable bits for /usr/bin/idle* (bsc#1227378). * Improve python reproducible builds (bsc#1227999) * Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660) * %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2089=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-2089=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2025-2089=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * python311-curses-debuginfo-3.11.9-150600.3.3.1 * python311-testsuite-3.11.9-150600.3.3.1 * python311-testsuite-debuginfo-3.11.9-150600.3.3.1 * python311-doc-3.11.9-150600.3.3.1 * python311-curses-3.11.9-150600.3.3.1 * python311-doc-devhelp-3.11.9-150600.3.3.1 * python311-base-3.11.9-150600.3.3.1 * python311-dbm-debuginfo-3.11.9-150600.3.3.1 * python311-3.11.9-150600.3.3.1 * libpython3_11-1_0-debuginfo-3.11.9-150600.3.3.1 * python311-tk-debuginfo-3.11.9-150600.3.3.1 * python311-dbm-3.11.9-150600.3.3.1 * python311-debuginfo-3.11.9-150600.3.3.1 * python311-devel-3.11.9-150600.3.3.1 * python311-debugsource-3.11.9-150600.3.3.1 * python311-base-debuginfo-3.11.9-150600.3.3.1 * python311-tools-3.11.9-150600.3.3.1 * python311-idle-3.11.9-150600.3.3.1 * python311-tk-3.11.9-150600.3.3.1 * openSUSE Leap 15.6 (x86_64) * libpython3_11-1_0-32bit-debuginfo-3.11.9-150600.3.3.1 * python311-32bit-debuginfo-3.11.9-150600.3.3.1 * python311-base-32bit-debuginfo-3.11.9-150600.3.3.1 * python311-base-32bit-3.11.9-150600.3.3.1 * libpython3_11-1_0-32bit-3.11.9-150600.3.3.1 * python311-32bit-3.11.9-150600.3.3.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * libpython3_11-1_0-debuginfo-3.11.9-150600.3.3.1 * python311-base-debuginfo-3.11.9-150600.3.3.1 * python311-base-3.11.9-150600.3.3.1 * Python 3 Module 15-SP6(aarch64 ppc64le s390x x86_64) * python311-3.11.9-150600.3.3.1 * python311-debuginfo-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * python311-devel-3.11.9-150600.3.3.1 * python311-debugsource-3.11.9-150600.3.3.1 * python311-curses-debuginfo-3.11.9-150600.3.3.1 * python311-tk-debuginfo-3.11.9-150600.3.3.1 * python311-curses-3.11.9-150600.3.3.1 * python311-tools-3.11.9-150600.3.3.1 * python311-idle-3.11.9-150600.3.3.1 * python311-dbm-debuginfo-3.11.9-150600.3.3.1 * python311-dbm-3.11.9-150600.3.3.1 * python311-tk-3.11.9-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0397.html * https://www.suse.com/security/cve/CVE-2024-4032.html * https://www.suse.com/security/cve/CVE-2024-6923.html * https://bugzilla.suse.com/show_bug.cgi?id=1225660 * https://bugzilla.suse.com/show_bug.cgi?id=1226447 * https://bugzilla.suse.com/show_bug.cgi?id=1226448 * https://bugzilla.suse.com/show_bug.cgi?id=1227378 * https://bugzilla.suse.com/show_bug.cgi?id=1227999 * https://bugzilla.suse.com/show_bug.cgi?id=1228780 . Essential python311 update addresses severe issues in SUSE Linux distros with three security fixes.. python security, SUSE updates, security patches, python vulnerabilities, system security. . Severity: Important. LinuxSecurity.com Team
* bsc#1228780 Cross-References: * CVE-2024-6923 . # Security update for python3 Announcement ID: SUSE-SU-2024:3294-1 Rating: important References: * bsc#1228780 Cross-References: * CVE-2024-6923 CVSS scores: * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * Web and Scripting Module 12 An update that solves one vulnerability can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2024-6923: email header injection due to unquoted newlines. (bsc#1228780) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-3294=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3294=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3294=1 * SUSELinux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-3294=1 * Web and Scripting Module 12 zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2024-3294=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * python3-devel-3.4.10-25.136.1 * python3-debugsource-3.4.10-25.136.1 * python3-dbm-debuginfo-3.4.10-25.136.1 * python3-base-debuginfo-3.4.10-25.136.1 * python3-base-debugsource-3.4.10-25.136.1 * python3-debuginfo-3.4.10-25.136.1 * python3-dbm-3.4.10-25.136.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.136.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * python3-devel-3.4.10-25.136.1 * python3-3.4.10-25.136.1 * python3-debugsource-3.4.10-25.136.1 * libpython3_4m1_0-3.4.10-25.136.1 * python3-base-debuginfo-3.4.10-25.136.1 * python3-curses-debuginfo-3.4.10-25.136.1 * python3-base-debugsource-3.4.10-25.136.1 * python3-tk-3.4.10-25.136.1 * python3-tk-debuginfo-3.4.10-25.136.1 * python3-base-3.4.10-25.136.1 * python3-debuginfo-3.4.10-25.136.1 * libpython3_4m1_0-debuginfo-3.4.10-25.136.1 * python3-curses-3.4.10-25.136.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.136.1 * python3-devel-debuginfo-3.4.10-25.136.1 * libpython3_4m1_0-32bit-3.4.10-25.136.1 * python3-base-debuginfo-32bit-3.4.10-25.136.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * python3-devel-3.4.10-25.136.1 * python3-3.4.10-25.136.1 * python3-debugsource-3.4.10-25.136.1 * libpython3_4m1_0-3.4.10-25.136.1 * python3-base-debuginfo-3.4.10-25.136.1 * python3-curses-debuginfo-3.4.10-25.136.1 * python3-base-debugsource-3.4.10-25.136.1 * python3-tk-3.4.10-25.136.1 * python3-tk-debuginfo-3.4.10-25.136.1 *python3-base-3.4.10-25.136.1 * python3-debuginfo-3.4.10-25.136.1 * libpython3_4m1_0-debuginfo-3.4.10-25.136.1 * python3-curses-3.4.10-25.136.1 * SUSE Linux Enterprise Server 12 SP5 (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.136.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.136.1 * libpython3_4m1_0-32bit-3.4.10-25.136.1 * python3-base-debuginfo-32bit-3.4.10-25.136.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * python3-devel-3.4.10-25.136.1 * python3-3.4.10-25.136.1 * python3-debugsource-3.4.10-25.136.1 * python3-devel-debuginfo-3.4.10-25.136.1 * libpython3_4m1_0-3.4.10-25.136.1 * python3-base-debuginfo-3.4.10-25.136.1 * python3-curses-debuginfo-3.4.10-25.136.1 * python3-base-debugsource-3.4.10-25.136.1 * python3-tk-3.4.10-25.136.1 * python3-tk-debuginfo-3.4.10-25.136.1 * python3-base-3.4.10-25.136.1 * python3-debuginfo-3.4.10-25.136.1 * libpython3_4m1_0-debuginfo-3.4.10-25.136.1 * python3-curses-3.4.10-25.136.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.136.1 * libpython3_4m1_0-32bit-3.4.10-25.136.1 * python3-base-debuginfo-32bit-3.4.10-25.136.1 * Web and Scripting Module 12 (aarch64 ppc64le s390x x86_64) * python3-3.4.10-25.136.1 * python3-debugsource-3.4.10-25.136.1 * libpython3_4m1_0-3.4.10-25.136.1 * python3-base-debuginfo-3.4.10-25.136.1 * python3-base-debugsource-3.4.10-25.136.1 * python3-base-3.4.10-25.136.1 * python3-debuginfo-3.4.10-25.136.1 * libpython3_4m1_0-debuginfo-3.4.10-25.136.1 * python3-curses-3.4.10-25.136.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6923.html * https://bugzilla.suse.com/show_bug.cgi?id=1228780 . A crucial patch has been issued to fix the email injection vulnerability in Python 3 for SUSE distributions. Follow these steps to enhance security..SUSE Linux, python3 update, email injection, SUSE security. . Severity: Important. LinuxSecurity.com Team
* bsc#1227233 * bsc#1227378 * bsc#1227999 * bsc#1228780 . # Security update for python39 Announcement ID: SUSE-SU-2024:3076-1 Rating: important References: * bsc#1227233 * bsc#1227378 * bsc#1227999 * bsc#1228780 Cross-References: * CVE-2024-5642 * CVE-2024-6923 CVSS scores: * CVE-2024-5642 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Legacy Module 15-SP5 * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities and has two security fixes can now be installed. ## Description: This update for python39 fixes the following issues: Security issues fixed: * CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-5642: Removed support for anything but OpenSSL 1.1.1 or newer (bsc#1227233) Non-security issues fixed: * Fixed executable bits for /usr/bin/idle* (bsc#1227378). * Improve python reproducible builds (bsc#1227999) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-3076=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-3076=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-3076=1 * openSUSE Leap 15.5 zypper in -tpatch openSUSE-SLE-15.5-2024-3076=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3076=1 * Legacy Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2024-3076=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-3076=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-3076=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * python39-3.9.19-150300.4.49.1 * python39-tk-3.9.19-150300.4.49.1 * python39-base-debuginfo-3.9.19-150300.4.49.1 * python39-curses-debuginfo-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * python39-debugsource-3.9.19-150300.4.49.1 * python39-idle-3.9.19-150300.4.49.1 * libpython3_9-1_0-3.9.19-150300.4.49.1 * python39-base-3.9.19-150300.4.49.1 * python39-core-debugsource-3.9.19-150300.4.49.1 * python39-tk-debuginfo-3.9.19-150300.4.49.1 * python39-debuginfo-3.9.19-150300.4.49.1 * python39-devel-3.9.19-150300.4.49.1 * python39-tools-3.9.19-150300.4.49.1 * python39-dbm-3.9.19-150300.4.49.1 * libpython3_9-1_0-debuginfo-3.9.19-150300.4.49.1 * python39-dbm-debuginfo-3.9.19-150300.4.49.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python39-3.9.19-150300.4.49.1 * python39-tk-3.9.19-150300.4.49.1 * python39-base-debuginfo-3.9.19-150300.4.49.1 * python39-curses-debuginfo-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * python39-debugsource-3.9.19-150300.4.49.1 * python39-idle-3.9.19-150300.4.49.1 * libpython3_9-1_0-3.9.19-150300.4.49.1 * python39-base-3.9.19-150300.4.49.1 * python39-core-debugsource-3.9.19-150300.4.49.1 * python39-tk-debuginfo-3.9.19-150300.4.49.1 * python39-debuginfo-3.9.19-150300.4.49.1 * python39-devel-3.9.19-150300.4.49.1 * python39-tools-3.9.19-150300.4.49.1 *python39-dbm-3.9.19-150300.4.49.1 * libpython3_9-1_0-debuginfo-3.9.19-150300.4.49.1 * python39-dbm-debuginfo-3.9.19-150300.4.49.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python39-3.9.19-150300.4.49.1 * python39-tk-3.9.19-150300.4.49.1 * python39-curses-debuginfo-3.9.19-150300.4.49.1 * libpython3_9-1_0-3.9.19-150300.4.49.1 * python39-dbm-3.9.19-150300.4.49.1 * python39-testsuite-debuginfo-3.9.19-150300.4.49.1 * python39-doc-devhelp-3.9.19-150300.4.49.1 * python39-base-debuginfo-3.9.19-150300.4.49.1 * python39-base-3.9.19-150300.4.49.1 * python39-tk-debuginfo-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * python39-idle-3.9.19-150300.4.49.1 * python39-core-debugsource-3.9.19-150300.4.49.1 * python39-devel-3.9.19-150300.4.49.1 * python39-testsuite-3.9.19-150300.4.49.1 * libpython3_9-1_0-debuginfo-3.9.19-150300.4.49.1 * python39-debugsource-3.9.19-150300.4.49.1 * python39-doc-3.9.19-150300.4.49.1 * python39-debuginfo-3.9.19-150300.4.49.1 * python39-tools-3.9.19-150300.4.49.1 * python39-dbm-debuginfo-3.9.19-150300.4.49.1 * openSUSE Leap 15.3 (x86_64) * libpython3_9-1_0-32bit-3.9.19-150300.4.49.1 * libpython3_9-1_0-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-base-32bit-3.9.19-150300.4.49.1 * python39-base-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-32bit-3.9.19-150300.4.49.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libpython3_9-1_0-64bit-debuginfo-3.9.19-150300.4.49.1 * python39-64bit-3.9.19-150300.4.49.1 * libpython3_9-1_0-64bit-3.9.19-150300.4.49.1 * python39-base-64bit-3.9.19-150300.4.49.1 * python39-64bit-debuginfo-3.9.19-150300.4.49.1 * python39-base-64bit-debuginfo-3.9.19-150300.4.49.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python39-3.9.19-150300.4.49.1 * python39-tk-3.9.19-150300.4.49.1 * python39-curses-debuginfo-3.9.19-150300.4.49.1 *libpython3_9-1_0-3.9.19-150300.4.49.1 * python39-dbm-3.9.19-150300.4.49.1 * python39-testsuite-debuginfo-3.9.19-150300.4.49.1 * python39-doc-devhelp-3.9.19-150300.4.49.1 * python39-base-debuginfo-3.9.19-150300.4.49.1 * python39-base-3.9.19-150300.4.49.1 * python39-tk-debuginfo-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * python39-idle-3.9.19-150300.4.49.1 * python39-core-debugsource-3.9.19-150300.4.49.1 * python39-devel-3.9.19-150300.4.49.1 * python39-testsuite-3.9.19-150300.4.49.1 * libpython3_9-1_0-debuginfo-3.9.19-150300.4.49.1 * python39-debugsource-3.9.19-150300.4.49.1 * python39-doc-3.9.19-150300.4.49.1 * python39-debuginfo-3.9.19-150300.4.49.1 * python39-tools-3.9.19-150300.4.49.1 * python39-dbm-debuginfo-3.9.19-150300.4.49.1 * openSUSE Leap 15.5 (x86_64) * libpython3_9-1_0-32bit-3.9.19-150300.4.49.1 * libpython3_9-1_0-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-base-32bit-3.9.19-150300.4.49.1 * python39-base-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-32bit-3.9.19-150300.4.49.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python39-3.9.19-150300.4.49.1 * python39-tk-3.9.19-150300.4.49.1 * python39-curses-debuginfo-3.9.19-150300.4.49.1 * libpython3_9-1_0-3.9.19-150300.4.49.1 * python39-dbm-3.9.19-150300.4.49.1 * python39-testsuite-debuginfo-3.9.19-150300.4.49.1 * python39-doc-devhelp-3.9.19-150300.4.49.1 * python39-base-debuginfo-3.9.19-150300.4.49.1 * python39-base-3.9.19-150300.4.49.1 * python39-tk-debuginfo-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * python39-idle-3.9.19-150300.4.49.1 * python39-core-debugsource-3.9.19-150300.4.49.1 * python39-devel-3.9.19-150300.4.49.1 * python39-testsuite-3.9.19-150300.4.49.1 * libpython3_9-1_0-debuginfo-3.9.19-150300.4.49.1 * python39-debugsource-3.9.19-150300.4.49.1 * python39-doc-3.9.19-150300.4.49.1 * python39-debuginfo-3.9.19-150300.4.49.1 * python39-tools-3.9.19-150300.4.49.1 * python39-dbm-debuginfo-3.9.19-150300.4.49.1 * openSUSE Leap 15.6 (x86_64) * libpython3_9-1_0-32bit-3.9.19-150300.4.49.1 * libpython3_9-1_0-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-base-32bit-3.9.19-150300.4.49.1 * python39-base-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-32bit-debuginfo-3.9.19-150300.4.49.1 * python39-32bit-3.9.19-150300.4.49.1 * Legacy Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python39-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * libpython3_9-1_0-3.9.19-150300.4.49.1 * python39-base-3.9.19-150300.4.49.1 * python39-dbm-3.9.19-150300.4.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * python39-3.9.19-150300.4.49.1 * python39-tk-3.9.19-150300.4.49.1 * python39-base-debuginfo-3.9.19-150300.4.49.1 * python39-curses-debuginfo-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * python39-debugsource-3.9.19-150300.4.49.1 * python39-idle-3.9.19-150300.4.49.1 * libpython3_9-1_0-3.9.19-150300.4.49.1 * python39-base-3.9.19-150300.4.49.1 * python39-core-debugsource-3.9.19-150300.4.49.1 * python39-tk-debuginfo-3.9.19-150300.4.49.1 * python39-debuginfo-3.9.19-150300.4.49.1 * python39-devel-3.9.19-150300.4.49.1 * python39-tools-3.9.19-150300.4.49.1 * python39-dbm-3.9.19-150300.4.49.1 * libpython3_9-1_0-debuginfo-3.9.19-150300.4.49.1 * python39-dbm-debuginfo-3.9.19-150300.4.49.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * python39-3.9.19-150300.4.49.1 * python39-tk-3.9.19-150300.4.49.1 * python39-base-debuginfo-3.9.19-150300.4.49.1 * python39-curses-debuginfo-3.9.19-150300.4.49.1 * python39-curses-3.9.19-150300.4.49.1 * python39-debugsource-3.9.19-150300.4.49.1 * python39-idle-3.9.19-150300.4.49.1 * libpython3_9-1_0-3.9.19-150300.4.49.1 *python39-base-3.9.19-150300.4.49.1 * python39-core-debugsource-3.9.19-150300.4.49.1 * python39-tk-debuginfo-3.9.19-150300.4.49.1 * python39-debuginfo-3.9.19-150300.4.49.1 * python39-devel-3.9.19-150300.4.49.1 * python39-tools-3.9.19-150300.4.49.1 * python39-dbm-3.9.19-150300.4.49.1 * libpython3_9-1_0-debuginfo-3.9.19-150300.4.49.1 * python39-dbm-debuginfo-3.9.19-150300.4.49.1 ## References: * https://www.suse.com/security/cve/CVE-2024-5642.html * https://www.suse.com/security/cve/CVE-2024-6923.html * https://bugzilla.suse.com/show_bug.cgi?id=1227233 * https://bugzilla.suse.com/show_bug.cgi?id=1227378 * https://bugzilla.suse.com/show_bug.cgi?id=1227999 * https://bugzilla.suse.com/show_bug.cgi?id=1228780 . Apply essential python39 security updates to mitigate email header injection vulnerabilities and enhance OpenSSL support within SUSE.. SUSE Security Advisory, Python Security, OpenSSL Fixes, Python Updates, Email Injection. . Severity: Important. LinuxSecurity.com Team
* bsc#1225660 * bsc#1226447 * bsc#1226448 * bsc#1227378 * bsc#1227999 . # Security update for python311 Announcement ID: SUSE-SU-2024:2982-1 Rating: important References: * bsc#1225660 * bsc#1226447 * bsc#1226448 * bsc#1227378 * bsc#1227999 * bsc#1228780 Cross-References: * CVE-2023-27043 * CVE-2024-0397 * CVE-2024-4032 * CVE-2024-6923 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-0397 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2024-4032 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities and has two security fixes can now be installed. ## Description: This update for python311 fixes the following issues: Security issues fixed: * CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-5642: Removed support for anything but OpenSSL 1.1.1 or newer (bsc#1227233) * CVE-2024-4032: Fixed incorrect IPv4 and IPv6 private ranges (bsc#1226448) Non-security issues fixed: * Fixed executable bits for /usr/bin/idle* (bsc#1227378). * Improve python reproducible builds (bsc#1227999) * Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660) * %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the commandlisted for your product: * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2024-2982=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-2982=1 openSUSE-SLE-15.6-2024-2982=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-2982=1 ## Package List: * Python 3 Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python311-3.11.9-150600.3.3.1 * python311-idle-3.11.9-150600.3.3.1 * python311-dbm-3.11.9-150600.3.3.1 * python311-devel-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * python311-debuginfo-3.11.9-150600.3.3.1 * python311-curses-3.11.9-150600.3.3.1 * python311-tk-3.11.9-150600.3.3.1 * python311-tk-debuginfo-3.11.9-150600.3.3.1 * python311-tools-3.11.9-150600.3.3.1 * python311-dbm-debuginfo-3.11.9-150600.3.3.1 * python311-curses-debuginfo-3.11.9-150600.3.3.1 * python311-debugsource-3.11.9-150600.3.3.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * python311-doc-devhelp-3.11.9-150600.3.3.1 * python311-dbm-3.11.9-150600.3.3.1 * python311-tk-3.11.9-150600.3.3.1 * python311-debuginfo-3.11.9-150600.3.3.1 * python311-tools-3.11.9-150600.3.3.1 * python311-testsuite-3.11.9-150600.3.3.1 * python311-base-3.11.9-150600.3.3.1 * python311-idle-3.11.9-150600.3.3.1 * libpython3_11-1_0-3.11.9-150600.3.3.1 * python311-curses-3.11.9-150600.3.3.1 * python311-doc-3.11.9-150600.3.3.1 * python311-3.11.9-150600.3.3.1 * python311-devel-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * python311-testsuite-debuginfo-3.11.9-150600.3.3.1 * python311-tk-debuginfo-3.11.9-150600.3.3.1 * libpython3_11-1_0-debuginfo-3.11.9-150600.3.3.1 * python311-dbm-debuginfo-3.11.9-150600.3.3.1 * python311-base-debuginfo-3.11.9-150600.3.3.1 * python311-curses-debuginfo-3.11.9-150600.3.3.1 * python311-debugsource-3.11.9-150600.3.3.1 * openSUSE Leap 15.6 (x86_64) *python311-32bit-3.11.9-150600.3.3.1 * python311-base-32bit-3.11.9-150600.3.3.1 * python311-32bit-debuginfo-3.11.9-150600.3.3.1 * libpython3_11-1_0-32bit-3.11.9-150600.3.3.1 * python311-base-32bit-debuginfo-3.11.9-150600.3.3.1 * libpython3_11-1_0-32bit-debuginfo-3.11.9-150600.3.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpython3_11-1_0-64bit-debuginfo-3.11.9-150600.3.3.1 * python311-64bit-debuginfo-3.11.9-150600.3.3.1 * python311-base-64bit-debuginfo-3.11.9-150600.3.3.1 * libpython3_11-1_0-64bit-3.11.9-150600.3.3.1 * python311-64bit-3.11.9-150600.3.3.1 * python311-base-64bit-3.11.9-150600.3.3.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libpython3_11-1_0-debuginfo-3.11.9-150600.3.3.1 * libpython3_11-1_0-3.11.9-150600.3.3.1 * python311-core-debugsource-3.11.9-150600.3.3.1 * python311-base-debuginfo-3.11.9-150600.3.3.1 * python311-base-3.11.9-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://www.suse.com/security/cve/CVE-2024-0397.html * https://www.suse.com/security/cve/CVE-2024-4032.html * https://www.suse.com/security/cve/CVE-2024-6923.html * https://bugzilla.suse.com/show_bug.cgi?id=1225660 * https://bugzilla.suse.com/show_bug.cgi?id=1226447 * https://bugzilla.suse.com/show_bug.cgi?id=1226448 * https://bugzilla.suse.com/show_bug.cgi?id=1227378 * https://bugzilla.suse.com/show_bug.cgi?id=1227999 * https://bugzilla.suse.com/show_bug.cgi?id=1228780 . Critical SUSE security patch for python311 addresses various vulnerabilities, including potential email header manipulation.. Security Updates, Python Issues, SUSE Linux Advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1225660 * bsc#1227378 * bsc#1227999 * bsc#1228780 . # Security update for python310 Announcement ID: SUSE-SU-2024:2974-1 Rating: important References: * bsc#1225660 * bsc#1227378 * bsc#1227999 * bsc#1228780 Cross-References: * CVE-2024-6923 CVSS scores: * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for python310 fixes the following issues: Security issue fixed: * CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780) Non-security issues fixed: * Improve python reproducible builds (bsc#1227999) * Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660) * Fixed executable bits for /usr/bin/idle* (bsc#1227378). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-2974=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2974=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-2974=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-2974=1 * SUSE LinuxEnterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-2974=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-2974=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-2974=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-2974=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-testsuite-debuginfo-3.10.14-150400.4.54.1 * python310-testsuite-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-debuginfo-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 * python310-idle-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-doc-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-doc-devhelp-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * openSUSE Leap 15.5 (x86_64) * python310-32bit-3.10.14-150400.4.54.1 * python310-base-32bit-debuginfo-3.10.14-150400.4.54.1 * python310-base-32bit-3.10.14-150400.4.54.1 * python310-32bit-debuginfo-3.10.14-150400.4.54.1 * libpython3_10-1_0-32bit-3.10.14-150400.4.54.1 * libpython3_10-1_0-32bit-debuginfo-3.10.14-150400.4.54.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-testsuite-debuginfo-3.10.14-150400.4.54.1 *python310-testsuite-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-debuginfo-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 * python310-idle-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-doc-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-doc-devhelp-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * openSUSE Leap 15.6 (x86_64) * python310-32bit-3.10.14-150400.4.54.1 * python310-base-32bit-debuginfo-3.10.14-150400.4.54.1 * python310-base-32bit-3.10.14-150400.4.54.1 * python310-32bit-debuginfo-3.10.14-150400.4.54.1 * libpython3_10-1_0-32bit-3.10.14-150400.4.54.1 * libpython3_10-1_0-32bit-debuginfo-3.10.14-150400.4.54.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 * python310-idle-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-dbm-debuginfo-3.10.14-150400.4.54.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 * python310-idle-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-dbm-debuginfo-3.10.14-150400.4.54.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 * python310-idle-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-dbm-debuginfo-3.10.14-150400.4.54.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 *python310-idle-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-dbm-debuginfo-3.10.14-150400.4.54.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 * python310-idle-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-dbm-debuginfo-3.10.14-150400.4.54.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * libpython3_10-1_0-3.10.14-150400.4.54.1 * python310-testsuite-debuginfo-3.10.14-150400.4.54.1 * python310-testsuite-3.10.14-150400.4.54.1 * python310-debugsource-3.10.14-150400.4.54.1 * python310-tk-debuginfo-3.10.14-150400.4.54.1 * python310-core-debugsource-3.10.14-150400.4.54.1 * python310-devel-3.10.14-150400.4.54.1 *python310-dbm-debuginfo-3.10.14-150400.4.54.1 * python310-base-3.10.14-150400.4.54.1 * python310-dbm-3.10.14-150400.4.54.1 * python310-debuginfo-3.10.14-150400.4.54.1 * python310-idle-3.10.14-150400.4.54.1 * python310-tk-3.10.14-150400.4.54.1 * python310-base-debuginfo-3.10.14-150400.4.54.1 * python310-curses-debuginfo-3.10.14-150400.4.54.1 * python310-3.10.14-150400.4.54.1 * python310-doc-3.10.14-150400.4.54.1 * libpython3_10-1_0-debuginfo-3.10.14-150400.4.54.1 * python310-curses-3.10.14-150400.4.54.1 * python310-doc-devhelp-3.10.14-150400.4.54.1 * python310-tools-3.10.14-150400.4.54.1 * openSUSE Leap 15.4 (x86_64) * python310-32bit-3.10.14-150400.4.54.1 * python310-base-32bit-debuginfo-3.10.14-150400.4.54.1 * python310-base-32bit-3.10.14-150400.4.54.1 * python310-32bit-debuginfo-3.10.14-150400.4.54.1 * libpython3_10-1_0-32bit-3.10.14-150400.4.54.1 * libpython3_10-1_0-32bit-debuginfo-3.10.14-150400.4.54.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_10-1_0-64bit-debuginfo-3.10.14-150400.4.54.1 * python310-base-64bit-3.10.14-150400.4.54.1 * python310-64bit-3.10.14-150400.4.54.1 * libpython3_10-1_0-64bit-3.10.14-150400.4.54.1 * python310-64bit-debuginfo-3.10.14-150400.4.54.1 * python310-base-64bit-debuginfo-3.10.14-150400.4.54.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6923.html * https://bugzilla.suse.com/show_bug.cgi?id=1225660 * https://bugzilla.suse.com/show_bug.cgi?id=1227378 * https://bugzilla.suse.com/show_bug.cgi?id=1227999 * https://bugzilla.suse.com/show_bug.cgi?id=1228780 . Important python310 security patch released for users of SUSE. Addresses email vulnerabilities and enhances build systems.. important Security Updates, python310 Security Patch, openSUSE Vulnerability. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.