The mailcap module does not add escape characters into commands discovered in the system mailcap file. (CVE-2015-20107) Allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. (CVE-2021-4189) . MGASA-2022-0367 - Updated python packages fix security vulnerability Publication date: 13 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0367.html Type: security Affected Mageia releases: 8 CVE: CVE-2015-20107, CVE-2021-4189, CVE-2022-0391 The mailcap module does not add escape characters into commands discovered in the system mailcap file. (CVE-2015-20107) Allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. (CVE-2021-4189) The urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. (CVE-2022-0391) References: - https://bugs.mageia.org/show_bug.cgi?id=30572 - https://lists.fedoraproject.org/archives/list/
Security fix for CVE-2015-20107. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-dbe9a8f9ac 2022-07-08 01:15:45.190364 --------------------------------------------------------------------------------Name : pypy3.9 Product : Fedora 36 Version : 7.3.9 Release : 2.3.9.fc36 URL : https://pypy.org/ Summary : Python 3.9 implementation with a Just-In-Time compiler Description : PyPy's implementation of Python 3.9, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc.). This build of PyPy has JIT-compilation enabled. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2015-20107 --------------------------------------------------------------------------------ChangeLog: * Tue Jun 28 2022 Charalampos Stratakis - 7.3.9-2.3.9 - Security fix for CVE-2015-20107 - Fixes: rhbz#2075390 --------------------------------------------------------------------------------References: [ 1 ] Bug #2076532 - CVE-2015-20107 pypy3.9: python(mailcap): findmatch() function does not sanitise the second argument [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2076532 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-dbe9a8f9ac' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
Security fix for CVE-2015-20107. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-ec74ac4079 2022-06-26 01:18:35.111743 --------------------------------------------------------------------------------Name : python2.7 Product : Fedora 35 Version : 2.7.18 Release : 22.fc35 URL : https://www.python.org/ Summary : Version 2.7 of the Python interpreter Description : Python 2 is an old version of the language that is incompatible with the 3.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed in the 3.x line. Note that Python 2 is not supported upstream after 2020-01-01, please use the python3 package instead if you can. This package also provides the "python2" executable. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2015-20107 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 9 2022 Charalampos Stratakis - 2.7.18-22 - Security fix for CVE-2015-20107 Resolves: rhbz#2075390 --------------------------------------------------------------------------------References: [ 1 ] Bug #2076509 - CVE-2015-20107 python2.7: python(mailcap): findmatch() function does not sanitise the second argument [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2076509 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-ec74ac4079' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2015-20107. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-4b0dfda810 2022-06-19 00:37:42.144179 --------------------------------------------------------------------------------Name : python3.6 Product : Fedora 36 Version : 3.6.15 Release : 9.fc36 URL : https://www.python.org/ Summary : Version 3.6 of the Python interpreter Description : Python 3.6 package for developers. This package exists to allow developers to test their code against an older version of Python. This is not a full Python stack and if you wish to run your applications with Python 3.6, see other distributions that support it, such as CentOS or RHEL with Software Collections or older Fedora releases. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2015-20107 --------------------------------------------------------------------------------ChangeLog: * Fri Jun 10 2022 Charalampos Stratakis - 3.6.15-9 - Security fix for CVE-2015-20107 Resolves: rhbz#2075390 --------------------------------------------------------------------------------References: [ 1 ] Bug #2076513 - CVE-2015-20107 python3.6: python(mailcap): findmatch() function does not sanitise the second argument [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2076513 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-4b0dfda810' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.