Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update python3 to 3.8.11 to fix several security issues. Fixes in 3.8.10 are also included. Bundled pip and setuptools were updated in 3.8.11 so python-pip needs to be updated to 21.1.3 and python-setuptools to 56.2.0 at the same time. . MGASA-2021-0386 - Updated python3 packages fix security vulnerabilities Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0386.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-29921 Update python3 to 3.8.11 to fix several security issues. Fixes in 3.8.10 are also included. Bundled pip and setuptools were updated in 3.8.11 so python-pip needs to be updated to 21.1.3 and python-setuptools to 56.2.0 at the same time. Also, we fix the following issue: In Python before 3.9.5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses (CVE-2021-29921). References: - https://bugs.mageia.org/show_bug.cgi?id=29288 - https://docs.python.org/release/3.8.11/whatsnew/changelog.html#changelog - https://docs.python.org/release/3.8.10/whatsnew/changelog.html#changelog - https://ubuntu.com/security/notices/USN-4973-1 - https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html - https://www.cve.org/CVERecord?id=CVE-2021-29921 SRPMS: - 8/core/python-pip-21.1.3-1.mga8 - 8/core/python-setuptools-56.2.0-1.mga8 - 8/core/python3-3.8.11-1.1.mga8 . Upgrade to python3 version 3.8.11 resolves vulnerabilities linked to IP address management issues. Also, ensure that pip and setuptools are upgraded accordingly.. Python3 Security Update, Mageia Advisory, Software Vulnerabilities. . LinuxSecurity.com Team
This update disallows use of IP addresses with leading zeroes in the octet values, which could have been interpreted ambiguously as either octal or decimal values.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-3393b2b19d 2021-04-24 20:00:51.077239 --------------------------------------------------------------------------------Name : perl-Net-CIDR-Lite Product : Fedora 34 Version : 0.22 Release : 1.fc34 URL : https://metacpan.org/dist/Net-CIDR-Lite Summary : Perl extension for merging IPv4 or IPv6 CIDR addresses Description : Faster alternative to Net::CIDR when merging a large number of CIDR address ranges. Works for IPv4 and IPv6 addresses. --------------------------------------------------------------------------------Update Information: This update disallows use of IP addresses with leading zeroes in the octet values, which could have been interpreted ambiguously as either octal or decimal values. --------------------------------------------------------------------------------ChangeLog: * Mon Apr 5 2021 Paul Howarth - 0.22-1 - Update to 0.22 - Security: IPv4 octets with leading zeroes are no longer allowed https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/ --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-3393b2b19d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.