It was discovered that incorrectly handled certain ZIP files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-9674). It was discovered that Python documentation had a misleading information. A security issue could be possibly caused by wrong assumptions of this . MGASA-2020-0451 - Updated python and python3 packages fix security vulnerabilities Publication date: 08 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0451.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-9674, CVE-2019-17514, CVE-2019-20907, CVE-2020-8492, CVE-2020-14422, CVE-2020-26116 It was discovered that incorrectly handled certain ZIP files. An attacker could possibly use this issue to cause a denial of service (CVE-2019-9674). It was discovered that Python documentation had a misleading information. A security issue could be possibly caused by wrong assumptions of this information (CVE-2019-17514). It was discovered that Python incorrectly handled certain TAR archives. An attacker could possibly use this issue to cause a denial of service (CVE-2019-20907). It was discovered that Python incorrectly handled certain HTTP requests. An attacker could possibly use this issue to cause a denial of service (CVE-2020-8492). It was discovered that Python incorrectly handled certain IP values. An attacker could possibly use this issue to cause a denial of service (CVE-2020-14422). It was discovered that Python incorrectly handled certain character sequences. A remote attacker could possibly use this issue to perform CRLF injection (CVE-2020-26116). The CVE-2020-14422 issue only affected python3. References: - https://bugs.mageia.org/show_bug.cgi?id=26268 - https://ubuntu.com/security/notices/USN-4428-1 - https://ubuntu.com/security/notices/USN-4333-1 - https://ubuntu.com/security/notices/USN-4581-1 - https://lists.fedoraproject.org/archives/list/
This is a maintenance and security update fixing various memory leaks, overflows, out-of-memory, heap overwriting and other issues. References: - https://bugs.mageia.org/show_bug.cgi?id=25256 . MGASA-2019-0228 - Updated graphicsmagick packages fix security issues Publication date: 31 Aug 2019 URL: https://advisories.mageia.org/MGASA-2019-0228.html Type: security Affected Mageia releases: 6, 7 This is a maintenance and security update fixing various memory leaks, overflows, out-of-memory, heap overwriting and other issues. References: - https://bugs.mageia.org/show_bug.cgi?id=25256 - http://www.graphicsmagick.org/NEWS.html#july-20-2019 SRPMS: - 6/core/graphicsmagick-1.3.33-1.mga6 - 7/core/graphicsmagick-1.3.33-1.mga7 . The latest advisory from Mageia, dated 2019-0228, highlights a crucial update for graphicsmagick that remedies existing memory leaks and other issues. Check the advisory for full details.. maintenance Update, memory overflow, heap overwriting, Mageia Security Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.