Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
172

Ubuntu 22.04/20.04/18.04 LTS: USN-7015-5 critical: python DoS

Several security issues were fixed in Python.. ========================================================================== Ubuntu Security Notice USN-7015-5 November 19, 2024 python2.7 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Python. Software Description: - python2.7: An interactive high-level object-oriented language Details: USN-7015-1 fixed several vulnerabilities in Python. This update provides the corresponding update for CVE-2024-6232 and CVE-2024-6923 for python2.7 in Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. Original advisory details: It was discovered that the Python email module incorrectly parsed email addresses that contain special characters. A remote attacker could possibly use this issue to bypass certain protection mechanisms. (CVE-2023-27043) It was discovered that Python allowed excessive backtracking while parsing certain tarfile headers. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. (CVE-2024-6232) It was discovered that the Python email module incorrectly quoted newlines for email headers. A remote attacker could possibly use this issue to perform header injection. (CVE-2024-6923) It was discovered that the Python http.cookies module incorrectly handled parsing cookies that contained backslashes for quoted characters. A remote attacker could possibly use this issue to cause Python to consume resources, leading to a denial of service. (CVE-2024-7592) It was discovered that the Python zipfile module incorrectly handled certain malformed zip files. A remote attacker could possibly use this issue to cause Python to stopresponding, resulting in a denial of service. (CVE-2024-8088) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS python2.7 2.7.18-13ubuntu1.3 python2.7-minimal 2.7.18-13ubuntu1.3 Ubuntu 20.04 LTS python2.7 2.7.18-1~20.04.5 python2.7-minimal 2.7.18-1~20.04.5 Ubuntu 18.04 LTS python2.7 2.7.17-1~18.04ubuntu1.13+esm7 Available with Ubuntu Pro python2.7-minimal 2.7.17-1~18.04ubuntu1.13+esm7 Available with Ubuntu Pro Ubuntu 16.04 LTS python2.7 2.7.12-1ubuntu0~16.04.18+esm12 Available with Ubuntu Pro python2.7-minimal 2.7.12-1ubuntu0~16.04.18+esm12 Available with Ubuntu Pro Ubuntu 14.04 LTS python2.7 2.7.6-8ubuntu0.6+esm21 Available with Ubuntu Pro python2.7-minimal 2.7.6-8ubuntu0.6+esm21 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7015-5 https://ubuntu.com/security/notices/USN-7015-4 https://ubuntu.com/security/notices/USN-7015-3 https://ubuntu.com/security/notices/USN-7015-2 https://ubuntu.com/security/notices/USN-7015-1 CVE-2024-6232, CVE-2024-6923 Package Information: https://launchpad.net/ubuntu/+source/python2.7/2.7.18-13ubuntu1.3 . Recent updates have addressed security flaws in Python across multiple Ubuntu LTS releases. Ensure your system is updated promptly to mitigate risks of DoS attacks.. Python Security, Ubuntu Security Advisory, Python Updates, DoS Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 19, 2024 Critical Ubuntu
100

SUSE: 2024:0784-1 Important: Python39 SSL Bypass Threat

* bsc#1196025 * bsc#1210638 * bsc#1212015 * bsc#1214692 * bsc#1215454 . # Security update for python39 Announcement ID: SUSE-SU-2024:0784-1 Rating: important References: * bsc#1196025 * bsc#1210638 * bsc#1212015 * bsc#1214692 * bsc#1215454 * bsc#1219666 * jsc#PED-7886 * jsc#SLE-21253 Cross-References: * CVE-2022-25236 * CVE-2023-27043 * CVE-2023-40217 * CVE-2023-6597 CVSS scores: * CVE-2022-25236 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2022-25236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-40217 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2023-40217 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2023-6597 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves four vulnerabilities, contains two features and has two security fixes can now be installed. ## Description: This update for python39 fixes the following issues: * CVE-2023-6597: Fixed symlink bug in cleanup of tempfile.TemporaryDirectory (bsc#1219666). * CVE-2023-27043: Fixed incorrect e-mqil parsing (bsc#1210638). * CVE-2023-40217: Fixed a ssl.SSLSocket TLS bypass vulnerability where data is sent unencrypted (bsc#1214692). * CVE-2022-25236: Fixed an expat vulnerability by supporting expat > = 2.4.4 (bsc#1212015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the commandlisted for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-784=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-784=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-784=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-784=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-784=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-784=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python39-core-debugsource-3.9.18-150300.4.38.1 * python39-tk-debuginfo-3.9.18-150300.4.38.1 * python39-debuginfo-3.9.18-150300.4.38.1 * python39-base-debuginfo-3.9.18-150300.4.38.1 * python39-devel-3.9.18-150300.4.38.1 * python39-curses-3.9.18-150300.4.38.1 * python39-doc-3.9.18-150300.4.38.1 * libpython3_9-1_0-debuginfo-3.9.18-150300.4.38.1 * python39-curses-debuginfo-3.9.18-150300.4.38.1 * python39-dbm-3.9.18-150300.4.38.1 * libpython3_9-1_0-3.9.18-150300.4.38.1 * python39-base-3.9.18-150300.4.38.1 * python39-tk-3.9.18-150300.4.38.1 * python39-idle-3.9.18-150300.4.38.1 * python39-3.9.18-150300.4.38.1 * python39-tools-3.9.18-150300.4.38.1 * python39-doc-devhelp-3.9.18-150300.4.38.1 * python39-testsuite-3.9.18-150300.4.38.1 * python39-debugsource-3.9.18-150300.4.38.1 * python39-dbm-debuginfo-3.9.18-150300.4.38.1 * python39-testsuite-debuginfo-3.9.18-150300.4.38.1 * openSUSE Leap 15.3 (x86_64) * libpython3_9-1_0-32bit-debuginfo-3.9.18-150300.4.38.1 * python39-32bit-debuginfo-3.9.18-150300.4.38.1 * python39-base-32bit-debuginfo-3.9.18-150300.4.38.1 * python39-32bit-3.9.18-150300.4.38.1 * libpython3_9-1_0-32bit-3.9.18-150300.4.38.1 * python39-base-32bit-3.9.18-150300.4.38.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libpython3_9-1_0-64bit-debuginfo-3.9.18-150300.4.38.1 *python39-base-64bit-debuginfo-3.9.18-150300.4.38.1 * libpython3_9-1_0-64bit-3.9.18-150300.4.38.1 * python39-64bit-debuginfo-3.9.18-150300.4.38.1 * python39-base-64bit-3.9.18-150300.4.38.1 * python39-64bit-3.9.18-150300.4.38.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python39-core-debugsource-3.9.18-150300.4.38.1 * python39-tk-debuginfo-3.9.18-150300.4.38.1 * python39-debuginfo-3.9.18-150300.4.38.1 * python39-base-debuginfo-3.9.18-150300.4.38.1 * python39-devel-3.9.18-150300.4.38.1 * python39-curses-3.9.18-150300.4.38.1 * python39-doc-3.9.18-150300.4.38.1 * libpython3_9-1_0-debuginfo-3.9.18-150300.4.38.1 * python39-curses-debuginfo-3.9.18-150300.4.38.1 * python39-dbm-3.9.18-150300.4.38.1 * libpython3_9-1_0-3.9.18-150300.4.38.1 * python39-base-3.9.18-150300.4.38.1 * python39-tk-3.9.18-150300.4.38.1 * python39-idle-3.9.18-150300.4.38.1 * python39-3.9.18-150300.4.38.1 * python39-tools-3.9.18-150300.4.38.1 * python39-doc-devhelp-3.9.18-150300.4.38.1 * python39-testsuite-3.9.18-150300.4.38.1 * python39-debugsource-3.9.18-150300.4.38.1 * python39-dbm-debuginfo-3.9.18-150300.4.38.1 * python39-testsuite-debuginfo-3.9.18-150300.4.38.1 * openSUSE Leap 15.5 (x86_64) * libpython3_9-1_0-32bit-debuginfo-3.9.18-150300.4.38.1 * python39-32bit-debuginfo-3.9.18-150300.4.38.1 * python39-base-32bit-debuginfo-3.9.18-150300.4.38.1 * python39-32bit-3.9.18-150300.4.38.1 * libpython3_9-1_0-32bit-3.9.18-150300.4.38.1 * python39-base-32bit-3.9.18-150300.4.38.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * python39-tk-3.9.18-150300.4.38.1 * python39-core-debugsource-3.9.18-150300.4.38.1 * python39-curses-3.9.18-150300.4.38.1 * python39-tk-debuginfo-3.9.18-150300.4.38.1 * python39-debuginfo-3.9.18-150300.4.38.1 * libpython3_9-1_0-debuginfo-3.9.18-150300.4.38.1 * python39-idle-3.9.18-150300.4.38.1 * python39-debugsource-3.9.18-150300.4.38.1 * python39-dbm-debuginfo-3.9.18-150300.4.38.1 * python39-3.9.18-150300.4.38.1 *python39-base-debuginfo-3.9.18-150300.4.38.1 * python39-curses-debuginfo-3.9.18-150300.4.38.1 * python39-devel-3.9.18-150300.4.38.1 * python39-dbm-3.9.18-150300.4.38.1 * libpython3_9-1_0-3.9.18-150300.4.38.1 * python39-base-3.9.18-150300.4.38.1 * python39-tools-3.9.18-150300.4.38.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * python39-tk-3.9.18-150300.4.38.1 * python39-core-debugsource-3.9.18-150300.4.38.1 * python39-curses-3.9.18-150300.4.38.1 * python39-tk-debuginfo-3.9.18-150300.4.38.1 * python39-debuginfo-3.9.18-150300.4.38.1 * libpython3_9-1_0-debuginfo-3.9.18-150300.4.38.1 * python39-idle-3.9.18-150300.4.38.1 * python39-debugsource-3.9.18-150300.4.38.1 * python39-dbm-debuginfo-3.9.18-150300.4.38.1 * python39-3.9.18-150300.4.38.1 * python39-base-debuginfo-3.9.18-150300.4.38.1 * python39-curses-debuginfo-3.9.18-150300.4.38.1 * python39-devel-3.9.18-150300.4.38.1 * python39-dbm-3.9.18-150300.4.38.1 * libpython3_9-1_0-3.9.18-150300.4.38.1 * python39-base-3.9.18-150300.4.38.1 * python39-tools-3.9.18-150300.4.38.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * python39-tk-3.9.18-150300.4.38.1 * python39-core-debugsource-3.9.18-150300.4.38.1 * python39-curses-3.9.18-150300.4.38.1 * python39-tk-debuginfo-3.9.18-150300.4.38.1 * python39-debuginfo-3.9.18-150300.4.38.1 * libpython3_9-1_0-debuginfo-3.9.18-150300.4.38.1 * python39-idle-3.9.18-150300.4.38.1 * python39-debugsource-3.9.18-150300.4.38.1 * python39-dbm-debuginfo-3.9.18-150300.4.38.1 * python39-3.9.18-150300.4.38.1 * python39-base-debuginfo-3.9.18-150300.4.38.1 * python39-curses-debuginfo-3.9.18-150300.4.38.1 * python39-devel-3.9.18-150300.4.38.1 * python39-dbm-3.9.18-150300.4.38.1 * libpython3_9-1_0-3.9.18-150300.4.38.1 * python39-base-3.9.18-150300.4.38.1 * python39-tools-3.9.18-150300.4.38.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python39-tk-3.9.18-150300.4.38.1 * python39-core-debugsource-3.9.18-150300.4.38.1 *python39-curses-3.9.18-150300.4.38.1 * python39-tk-debuginfo-3.9.18-150300.4.38.1 * python39-debuginfo-3.9.18-150300.4.38.1 * libpython3_9-1_0-debuginfo-3.9.18-150300.4.38.1 * python39-idle-3.9.18-150300.4.38.1 * python39-debugsource-3.9.18-150300.4.38.1 * python39-dbm-debuginfo-3.9.18-150300.4.38.1 * python39-3.9.18-150300.4.38.1 * python39-base-debuginfo-3.9.18-150300.4.38.1 * python39-curses-debuginfo-3.9.18-150300.4.38.1 * python39-devel-3.9.18-150300.4.38.1 * python39-dbm-3.9.18-150300.4.38.1 * libpython3_9-1_0-3.9.18-150300.4.38.1 * python39-base-3.9.18-150300.4.38.1 * python39-tools-3.9.18-150300.4.38.1 ## References: * https://www.suse.com/security/cve/CVE-2022-25236.html * https://www.suse.com/security/cve/CVE-2023-27043.html * https://www.suse.com/security/cve/CVE-2023-40217.html * https://www.suse.com/security/cve/CVE-2023-6597.html * https://bugzilla.suse.com/show_bug.cgi?id=1196025 * https://bugzilla.suse.com/show_bug.cgi?id=1210638 * https://bugzilla.suse.com/show_bug.cgi?id=1212015 * https://bugzilla.suse.com/show_bug.cgi?id=1214692 * https://bugzilla.suse.com/show_bug.cgi?id=1215454 * https://bugzilla.suse.com/show_bug.cgi?id=1219666 * * . Tackling vital safety concerns in python39, encompassing solutions for information exposure and mail parsing flaws on SUSE environments.. Python Update,SUSE Security,Python39 TLS Fix,OpenSUSE Patch,Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 06, 2024 Important SuSE
100

SUSE: 2024:0329-2 Moderate: Email Parsing Flaw in Python

* bsc#1210638 Cross-References: * CVE-2023-27043 . # Security update for python Announcement ID: SUSE-SU-2024:0329-2 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP4 An update that solves one vulnerability can now be installed. ## Description: This update for python fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP4 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2024-329=1 ## Package List: * SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x x86_64) * python-debuginfo-2.7.18-150000.60.1 * python-base-debugsource-2.7.18-150000.60.1 * python-devel-2.7.18-150000.60.1 * python-xml-2.7.18-150000.60.1 * python-curses-2.7.18-150000.60.1 * python-2.7.18-150000.60.1 * libpython2_7-1_0-2.7.18-150000.60.1 * python-curses-debuginfo-2.7.18-150000.60.1 * python-gdbm-debuginfo-2.7.18-150000.60.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.60.1 * python-base-2.7.18-150000.60.1 * python-base-debuginfo-2.7.18-150000.60.1 *python-gdbm-2.7.18-150000.60.1 * python-tk-debuginfo-2.7.18-150000.60.1 * python-debugsource-2.7.18-150000.60.1 * python-xml-debuginfo-2.7.18-150000.60.1 * python-tk-2.7.18-150000.60.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . SUSE has launched a crucial security update addressing multiple vulnerabilities, particularly email parsing flaws related to CVE-2023-27043, enhancing Python app safety.. SUSE Linux Enterprise, python updates, python security patches. . LinuxSecurity.com Team

Calendar%202 Mar 05, 2024 SuSE
202

openSUSE: 2024:0581-1 moderate: python3 email address parsing issue

This update for python3 fixes the following issues: CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638).. # Security update for python3 Announcement ID: SUSE-SU-2024:0581-1 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP5 * Development Tools Module 15-SP5 * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-581=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-581=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-581=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-581=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-581=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-581=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-581=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-581=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-581=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-581=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-581=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-581=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-581=1 ## Package List: * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-devel-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-devel-debuginfo-3.6.15-150300.10.54.1 * python3-tk-debuginfo-3.6.15-150300.10.54.1 * python3-curses-debuginfo-3.6.15-150300.10.54.1 * python3-dbm-3.6.15-150300.10.54.1 * python3-dbm-debuginfo-3.6.15-150300.10.54.1 * python3-curses-3.6.15-150300.10.54.1 * python3-tk-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-idle-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-tools-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 *python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python3-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-dbm-3.6.15-150300.10.54.1 * python3-testsuite-debuginfo-3.6.15-150300.10.54.1 * python3-doc-devhelp-3.6.15-150300.10.54.1 * python3-idle-3.6.15-150300.10.54.1 * python3-doc-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-devel-3.6.15-150300.10.54.1 * python3-curses-debuginfo-3.6.15-150300.10.54.1 * python3-dbm-debuginfo-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-devel-debuginfo-3.6.15-150300.10.54.1 * python3-tk-debuginfo-3.6.15-150300.10.54.1 * python3-tools-3.6.15-150300.10.54.1 * python3-tk-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * python3-testsuite-3.6.15-150300.10.54.1 * python3-curses-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.3 (x86_64) * libpython3_6m1_0-32bit-3.6.15-150300.10.54.1 * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.54.1 * openSUSE Leap 15.3 (aarch64_ilp32) *libpython3_6m1_0-64bit-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-64bit-3.6.15-150300.10.54.1 * openSUSE Leap Micro 5.3 (aarch64 x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-dbm-3.6.15-150300.10.54.1 * python3-testsuite-debuginfo-3.6.15-150300.10.54.1 * python3-doc-devhelp-3.6.15-150300.10.54.1 * python3-idle-3.6.15-150300.10.54.1 * python3-doc-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-devel-3.6.15-150300.10.54.1 * python3-curses-debuginfo-3.6.15-150300.10.54.1 * python3-dbm-debuginfo-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-devel-debuginfo-3.6.15-150300.10.54.1 * python3-tk-debuginfo-3.6.15-150300.10.54.1 * python3-tools-3.6.15-150300.10.54.1 * python3-tk-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * python3-testsuite-3.6.15-150300.10.54.1 * python3-curses-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.5(x86_64) * libpython3_6m1_0-32bit-3.6.15-150300.10.54.1 * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . A patch for python3 targeting CVE-2023-27043 has been released to rectify email address parsing vulnerabilities in openSUSE.. python3 update, openSUSE security, email parsing fix, moderate threat. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2024 OpenSUSE
100

SUSE: 2024:0464-1 Moderate Security Update for Python3 Email Parsing

* bsc#1210638 * bsc#1214691 Cross-References: * CVE-2022-48566 . # Security update for python3 Announcement ID: SUSE-SU-2024:0464-1 Rating: moderate References: * bsc#1210638 * bsc#1214691 Cross-References: * CVE-2022-48566 * CVE-2023-27043 CVSS scores: * CVE-2022-48566 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2022-48566 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). * CVE-2022-48566: Use CRYPTO_memcmp() for compare_digest (bsc#1214691). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2024-464=1 ## Package List: * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * python3-debugsource-3.6.15-150000.3.138.1 * python3-core-debugsource-3.6.15-150000.3.138.1 * python3-base-3.6.15-150000.3.138.1 * libpython3_6m1_0-3.6.15-150000.3.138.1 * python3-debuginfo-3.6.15-150000.3.138.1 * python3-base-debuginfo-3.6.15-150000.3.138.1 * libpython3_6m1_0-debuginfo-3.6.15-150000.3.138.1 * python3-3.6.15-150000.3.138.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48566.html * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 * https://bugzilla.suse.com/show_bug.cgi?id=1214691 . A vital patch has been released for python3 to tackle severevulnerabilities in email handling and encryption mechanisms within SUSE systems.. python3 Security Update, SUSE Python Threats, Python Security Fixes. . LinuxSecurity.com Team

Calendar%202 Feb 14, 2024 SuSE
100

SUSE Linux 12 SP5: 2024:0438-1 Moderate: Python3 Email Parsing Error

* bsc#1210638 Cross-References: * CVE-2023-27043 . # Security update for python3 Announcement ID: SUSE-SU-2024:0438-1 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * Web and Scripting Module 12 An update that solves one vulnerability can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 12 zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2024-438=1 * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-438=1 * SUSE Linux EnterpriseHigh Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-438=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-438=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-438=1 ## Package List: * Web and Scripting Module 12 (aarch64 ppc64le s390x x86_64) * python3-debuginfo-3.4.10-25.119.1 * python3-base-3.4.10-25.119.1 * python3-3.4.10-25.119.1 * libpython3_4m1_0-debuginfo-3.4.10-25.119.1 * libpython3_4m1_0-3.4.10-25.119.1 * python3-curses-3.4.10-25.119.1 * python3-base-debugsource-3.4.10-25.119.1 * python3-base-debuginfo-3.4.10-25.119.1 * python3-debugsource-3.4.10-25.119.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * python3-debuginfo-3.4.10-25.119.1 * python3-devel-3.4.10-25.119.1 * python3-dbm-debuginfo-3.4.10-25.119.1 * python3-dbm-3.4.10-25.119.1 * python3-base-debugsource-3.4.10-25.119.1 * python3-base-debuginfo-3.4.10-25.119.1 * python3-debugsource-3.4.10-25.119.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.119.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * python3-debuginfo-3.4.10-25.119.1 * python3-base-3.4.10-25.119.1 * python3-tk-debuginfo-3.4.10-25.119.1 * python3-3.4.10-25.119.1 * python3-devel-3.4.10-25.119.1 * libpython3_4m1_0-debuginfo-3.4.10-25.119.1 * libpython3_4m1_0-3.4.10-25.119.1 * python3-tk-3.4.10-25.119.1 * python3-curses-3.4.10-25.119.1 * python3-base-debugsource-3.4.10-25.119.1 * python3-base-debuginfo-3.4.10-25.119.1 * python3-debugsource-3.4.10-25.119.1 * python3-curses-debuginfo-3.4.10-25.119.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * python3-base-debuginfo-32bit-3.4.10-25.119.1 * python3-devel-debuginfo-3.4.10-25.119.1 *libpython3_4m1_0-debuginfo-32bit-3.4.10-25.119.1 * libpython3_4m1_0-32bit-3.4.10-25.119.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * python3-debuginfo-3.4.10-25.119.1 * python3-base-3.4.10-25.119.1 * python3-tk-debuginfo-3.4.10-25.119.1 * python3-3.4.10-25.119.1 * python3-devel-3.4.10-25.119.1 * libpython3_4m1_0-debuginfo-3.4.10-25.119.1 * libpython3_4m1_0-3.4.10-25.119.1 * python3-tk-3.4.10-25.119.1 * python3-curses-3.4.10-25.119.1 * python3-base-debugsource-3.4.10-25.119.1 * python3-base-debuginfo-3.4.10-25.119.1 * python3-debugsource-3.4.10-25.119.1 * python3-curses-debuginfo-3.4.10-25.119.1 * SUSE Linux Enterprise Server 12 SP5 (ppc64le s390x x86_64) * python3-devel-debuginfo-3.4.10-25.119.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * python3-base-debuginfo-32bit-3.4.10-25.119.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.119.1 * libpython3_4m1_0-32bit-3.4.10-25.119.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * python3-debuginfo-3.4.10-25.119.1 * python3-base-3.4.10-25.119.1 * python3-tk-debuginfo-3.4.10-25.119.1 * python3-3.4.10-25.119.1 * python3-devel-3.4.10-25.119.1 * libpython3_4m1_0-debuginfo-3.4.10-25.119.1 * libpython3_4m1_0-3.4.10-25.119.1 * python3-tk-3.4.10-25.119.1 * python3-curses-3.4.10-25.119.1 * python3-devel-debuginfo-3.4.10-25.119.1 * python3-base-debugsource-3.4.10-25.119.1 * python3-base-debuginfo-3.4.10-25.119.1 * python3-debugsource-3.4.10-25.119.1 * python3-curses-debuginfo-3.4.10-25.119.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * python3-base-debuginfo-32bit-3.4.10-25.119.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.119.1 * libpython3_4m1_0-32bit-3.4.10-25.119.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . Essential security patch released forpython3 tackling email handling vulnerabilities in SUSE systems. Please implement required measures immediately.. SUSE Linux, Python3, Security Update, Email Parsing Issue, Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 09, 2024 Important SuSE
100

SUSE: 2024:0436-1 Moderate: Python36 Email Parsing Correction

* bsc#1210638 Cross-References: * CVE-2023-27043 . # Security update for python36 Announcement ID: SUSE-SU-2024:0436-1 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python36 fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-436=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-436=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-436=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-436=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * python36-devel-3.6.15-52.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * python36-debuginfo-3.6.15-52.1 * libpython3_6m1_0-3.6.15-52.1 * python36-3.6.15-52.1 * python36-base-debuginfo-3.6.15-52.1 * libpython3_6m1_0-debuginfo-3.6.15-52.1 * python36-base-3.6.15-52.1 * python36-debugsource-3.6.15-52.1 * SUSE LinuxEnterprise High Performance Computing 12 SP5 (x86_64) * libpython3_6m1_0-32bit-3.6.15-52.1 * libpython3_6m1_0-debuginfo-32bit-3.6.15-52.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * python36-debuginfo-3.6.15-52.1 * libpython3_6m1_0-3.6.15-52.1 * python36-3.6.15-52.1 * python36-base-debuginfo-3.6.15-52.1 * libpython3_6m1_0-debuginfo-3.6.15-52.1 * python36-base-3.6.15-52.1 * python36-debugsource-3.6.15-52.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * libpython3_6m1_0-32bit-3.6.15-52.1 * libpython3_6m1_0-debuginfo-32bit-3.6.15-52.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * python36-debuginfo-3.6.15-52.1 * libpython3_6m1_0-3.6.15-52.1 * python36-3.6.15-52.1 * python36-base-debuginfo-3.6.15-52.1 * libpython3_6m1_0-debuginfo-3.6.15-52.1 * python36-base-3.6.15-52.1 * python36-debugsource-3.6.15-52.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * libpython3_6m1_0-32bit-3.6.15-52.1 * libpython3_6m1_0-debuginfo-32bit-3.6.15-52.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . This release resolves a significant vulnerability in python36 associated with email validation on Ubuntu platforms.. Python36 Security Update, SUSE Linux Advisory, Email Parsing Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 08, 2024 Important SuSE
100

SUSE Linux Enterprise: 2024:0437-1 Moderate Python Email Parsing Fix

* bsc#1210638 Cross-References: * CVE-2023-27043 . # Security update for python Announcement ID: SUSE-SU-2024:0437-1 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-437=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-437=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-437=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-437=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * python-debuginfo-2.7.18-33.29.1 * python-tk-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-2.7.18-33.29.1 * python-gdbm-2.7.18-33.29.1 * python-curses-debuginfo-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 * python-base-debuginfo-2.7.18-33.29.1 * python-gdbm-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-2.7.18-33.29.1 * python-demo-2.7.18-33.29.1 *python-tk-2.7.18-33.29.1 * python-debugsource-2.7.18-33.29.1 * python-xml-2.7.18-33.29.1 * python-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-xml-debuginfo-2.7.18-33.29.1 * python-base-2.7.18-33.29.1 * python-curses-2.7.18-33.29.1 * python-idle-2.7.18-33.29.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * python-doc-2.7.18-33.29.1 * python-doc-pdf-2.7.18-33.29.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * python-base-32bit-2.7.18-33.29.1 * python-base-debuginfo-32bit-2.7.18-33.29.1 * libpython2_7-1_0-32bit-2.7.18-33.29.1 * python-debuginfo-32bit-2.7.18-33.29.1 * python-32bit-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-32bit-2.7.18-33.29.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * python-debuginfo-2.7.18-33.29.1 * python-tk-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-2.7.18-33.29.1 * python-gdbm-2.7.18-33.29.1 * python-curses-debuginfo-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 * python-base-debuginfo-2.7.18-33.29.1 * python-gdbm-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-2.7.18-33.29.1 * python-demo-2.7.18-33.29.1 * python-tk-2.7.18-33.29.1 * python-debugsource-2.7.18-33.29.1 * python-xml-2.7.18-33.29.1 * python-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-xml-debuginfo-2.7.18-33.29.1 * python-base-2.7.18-33.29.1 * python-curses-2.7.18-33.29.1 * python-idle-2.7.18-33.29.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * python-doc-2.7.18-33.29.1 * python-doc-pdf-2.7.18-33.29.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * python-base-32bit-2.7.18-33.29.1 * python-base-debuginfo-32bit-2.7.18-33.29.1 * libpython2_7-1_0-32bit-2.7.18-33.29.1 * python-debuginfo-32bit-2.7.18-33.29.1 * python-32bit-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-32bit-2.7.18-33.29.1 * SUSE Linux Enterprise Server for SAPApplications 12 SP5 (ppc64le x86_64) * python-debuginfo-2.7.18-33.29.1 * python-tk-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-2.7.18-33.29.1 * python-gdbm-2.7.18-33.29.1 * python-curses-debuginfo-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 * python-base-debuginfo-2.7.18-33.29.1 * python-gdbm-debuginfo-2.7.18-33.29.1 * python-xml-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-2.7.18-33.29.1 * python-demo-2.7.18-33.29.1 * python-tk-2.7.18-33.29.1 * python-xml-2.7.18-33.29.1 * python-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-debugsource-2.7.18-33.29.1 * python-base-2.7.18-33.29.1 * python-curses-2.7.18-33.29.1 * python-idle-2.7.18-33.29.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * python-doc-2.7.18-33.29.1 * python-doc-pdf-2.7.18-33.29.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * python-base-32bit-2.7.18-33.29.1 * python-base-debuginfo-32bit-2.7.18-33.29.1 * libpython2_7-1_0-32bit-2.7.18-33.29.1 * python-debuginfo-32bit-2.7.18-33.29.1 * python-32bit-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-32bit-2.7.18-33.29.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * python-base-debuginfo-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . This announcement highlights a significant enhancement for Java that focuses on CVE-2023-29015 concerning network security in multiple Fedora distributions.. Python Update, SUSE Security, Email Parsing Issues, Software Patch Update. . LinuxSecurity.com Team

Calendar%202 Feb 08, 2024 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200