Multiple vulnerabilities have been found in Python, the worst of which might allow attackers to access sensitive information.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202104-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Python: Multiple vulnerabilities Date: April 30, 2021 Bugs: #770853, #779841, #779844 ID: 202104-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Python, the worst of which might allow attackers to access sensitive information. Background ========= Python is an interpreted, interactive, object-oriented programming language. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/python < 3.9.2_p1 > = 2.7.18_p8:2.7 > = 3.6.13_p1:3.6 > = 3.7.10_p1:3.7 > = 3.8.8_p1:3.8 > = 3.9.2_p1:3.9 Description ========== Multiple vulnerabilities have been discovered in Python. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All Python 2.7 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/python-2.7.18_p8" All Python 3.6 usersshould upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/python-3.6.13_p1" All Python 3.7 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/python-3.7.10_p1" All Python 3.8 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/python-3.8.8_p1" All Python 3.9 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/python-3.9.2_p1" References ========= [ 1 ] CVE-2021-23336 https://nvd.nist.gov/vuln/detail/CVE-2021-23336 [ 2 ] CVE-2021-3426 https://nvd.nist.gov/vuln/detail/CVE-2021-3426 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202104-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.