Moderate: python27:2.7 security and bug fix update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:7042", "synopsis": "Moderate: python27:2.7 security and bug fix update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for python-mock, module.python-sqlalchemy, python-backports-ssl_match_hostname, python-attrs, python-chardet, python2-rpm-macros, module.numpy, module.python-mock, python-pymongo, python-markupsafe, python-psycopg2, python2-six, module.python-funcsigs, module.python-pygments, module.pytz, python-coverage, module.python-chardet, module.python-pluggy, module.python-virtualenv, module.python-PyMySQL, python-PyMySQL, module.python-dns, module.python-nose, python-pysocks, python-funcsigs, scipy, module.python-pytest-mock, module.python-attrs, numpy, python-wheel, PyYAML, module.python-docs, module.python-setuptools_scm, module.python-backports-ssl_match_hostname, babel, python-idna, python2-pip, module.python-wheel, module.python-ipaddress, module.python-markupsafe, module.python-psycopg2, python-requests, module.scipy, module.PyYAML, python-nose, module.Cython, module.python-lxml, python-sqlalchemy, module.python2-pip, python-dns, pytest, module.python-backports, module.python-coverage, module.babel, python-pluggy, module.python-docutils, module.python-requests, python-pygments, module.python-pymongo, module.python2-six, module.python-pysocks, pytz, python-docs, python-backports, python-py, python-lxml, python-pytest-mock, module.pytest, python-setuptools_scm, module.python-idna, module.python-py, python-ipaddress, Cython, module.python2-rpm-macros, python-docutils.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing. The python27 packages providea stable release of Python 2.7 with a number of additional utilities and database connectors for MySQL and PostgreSQL.\n\nSecurity Fix(es):\n\n* python-requests: Unintended leak of Proxy-Authorization header (CVE-2023-32681)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nAdditional Changes:\n\nFor detailed information on changes in this release, see the Rocky Linux 8.9 Release Notes linked from the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2209469", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2209469", "description": ""}], "cves": [{"name": "CVE-2023-32681", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-32681", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-402"}], "references": [], "publishedAt": "2026-03-18T06:01:13.733535Z", "rpms": {"Rocky Linux 8": {"nvras": ["babel-0:2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "babel-0:2.5.1-10.module+el8.9.0+1531+a18208f5.src.rpm", "Cython-0:0.28.1-7.module+el8.9.0+1531+a18208f5.src.rpm", "Cython-debugsource-0:0.28.1-7.module+el8.9.0+1531+a18208f5.aarch64.rpm", "Cython-debugsource-0:0.28.1-7.module+el8.9.0+1531+a18208f5.x86_64.rpm", "numpy-1:1.14.2-16.module+el8.9.0+1531+a18208f5.src.rpm", "numpy-debugsource-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "numpy-debugsource-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "pytest-0:3.4.2-13.module+el8.9.0+1531+a18208f5.src.rpm", "python2-attrs-0:17.4.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-babel-0:2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-backports-0:1.0-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-backports-0:1.0-16.module+el8.9.0+1531+a18208f5.x86_64.rpm","python2-backports-ssl_match_hostname-0:3.5.0.1-12.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-bson-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-bson-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-bson-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-bson-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-chardet-0:3.0.4-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-coverage-0:4.5.1-5.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-coverage-0:4.5.1-5.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-nose-0:1.3.7-31.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-coverage-debuginfo-0:4.5.1-5.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-coverage-debuginfo-0:4.5.1-5.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-Cython-0:0.28.1-7.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-Cython-0:0.28.1-7.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-Cython-debuginfo-0:0.28.1-7.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-Cython-debuginfo-0:0.28.1-7.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-dns-0:1.15.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-docs-0:2.7.16-2.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-docs-info-0:2.7.16-2.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-docutils-0:0.14-12.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-funcsigs-0:1.0.2-13.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-idna-0:2.5-7.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-ipaddress-0:1.0.18-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-lxml-0:4.2.3-6.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-lxml-0:4.2.3-6.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-lxml-debuginfo-0:4.2.3-6.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-lxml-debuginfo-0:4.2.3-6.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-markupsafe-0:0.23-19.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-markupsafe-0:0.23-19.module+el8.9.0+1531+a18208f5.x86_64.rpm","python2-mock-0:2.0.0-13.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-numpy-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-numpy-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-numpy-debuginfo-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-numpy-debuginfo-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-numpy-doc-1:1.14.2-16.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-numpy-f2py-1:1.14.2-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-numpy-f2py-1:1.14.2-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pip-0:9.0.3-19.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pip-0:9.0.3-19.module+el8.9.0+1531+a18208f5.src.rpm", "python2-pip-wheel-0:9.0.3-19.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pluggy-0:0.6.0-8.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-psycopg2-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-debug-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-debug-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-debug-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-debug-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-psycopg2-tests-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-psycopg2-tests-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-py-0:1.5.3-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pygments-0:2.2.0-22.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pymongo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pymongo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm","python2-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pymongo-gridfs-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pymongo-gridfs-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-PyMySQL-0:0.8.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pysocks-0:1.6.8-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pytest-0:3.4.2-13.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pytest-mock-0:1.9.0-4.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-pytz-0:2017.2-13.module+el8.10.0+1817+0b01df83.noarch.rpm", "python2-pyyaml-0:3.12-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pyyaml-0:3.12-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-pyyaml-debuginfo-0:3.12-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-pyyaml-debuginfo-0:3.12-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-requests-0:2.20.0-4.module+el8.10.0+1817+0b01df83.noarch.rpm", "python2-rpm-macros-0:3-38.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-rpm-macros-0:3-38.module+el8.9.0+1531+a18208f5.src.rpm", "python2-scipy-0:1.0.0-22.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-scipy-0:1.0.0-22.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-scipy-debuginfo-0:1.0.0-22.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python2-scipy-debuginfo-0:1.0.0-22.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python2-setuptools_scm-0:1.15.7-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-six-0:1.11.0-6.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-six-0:1.11.0-6.module+el8.9.0+1531+a18208f5.src.rpm", "python2-sqlalchemy-0:1.3.2-2.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python2-sqlalchemy-0:1.3.2-2.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python2-wheel-1:0.31.1-3.module+el8.9.0+1531+a18208f5.noarch.rpm", "python2-wheel-wheel-1:0.31.1-3.module+el8.9.0+1531+a18208f5.noarch.rpm", "python-attrs-0:17.4.0-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-backports-0:1.0-16.module+el8.9.0+1531+a18208f5.src.rpm","python-backports-ssl_match_hostname-0:3.5.0.1-12.module+el8.9.0+1531+a18208f5.src.rpm", "python-chardet-0:3.0.4-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-coverage-0:4.5.1-5.module+el8.10.0+1817+0b01df83.src.rpm", "python-coverage-debugsource-0:4.5.1-5.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python-coverage-debugsource-0:4.5.1-5.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-dns-0:1.15.0-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-docs-0:2.7.16-2.module+el8.9.0+1531+a18208f5.src.rpm", "python-docutils-0:0.14-12.module+el8.10.0+1910+234ad790.src.rpm", "python-docutils-0:0.14-12.module+el8.9.0+1531+a18208f5.src.rpm", "python-funcsigs-0:1.0.2-13.module+el8.9.0+1531+a18208f5.src.rpm", "python-idna-0:2.5-7.module+el8.9.0+1531+a18208f5.src.rpm", "python-ipaddress-0:1.0.18-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-lxml-0:4.2.3-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-lxml-debugsource-0:4.2.3-6.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python-lxml-debugsource-0:4.2.3-6.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python-markupsafe-0:0.23-19.module+el8.9.0+1531+a18208f5.src.rpm", "python-mock-0:2.0.0-13.module+el8.9.0+1531+a18208f5.src.rpm", "python-nose-0:1.3.7-31.module+el8.10.0+1910+234ad790.src.rpm", "python-nose-0:1.3.7-31.module+el8.9.0+1531+a18208f5.src.rpm", "python-nose-docs-0:1.3.7-31.module+el8.10.0+1910+234ad790.noarch.rpm", "python-nose-docs-0:1.3.7-31.module+el8.9.0+1531+a18208f5.noarch.rpm", "python-pluggy-0:0.6.0-8.module+el8.9.0+1531+a18208f5.src.rpm", "python-psycopg2-0:2.7.5-8.module+el8.10.0+1817+0b01df83.src.rpm", "python-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python-psycopg2-debuginfo-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-psycopg2-debugsource-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm", "python-psycopg2-debugsource-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-psycopg2-doc-0:2.7.5-8.module+el8.10.0+1817+0b01df83.aarch64.rpm","python-psycopg2-doc-0:2.7.5-8.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-py-0:1.5.3-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-pygments-0:2.2.0-22.module+el8.10.0+1910+234ad790.src.rpm", "python-pygments-0:2.2.0-22.module+el8.9.0+1531+a18208f5.src.rpm", "python-pymongo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.src.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.9.0+1531+a18208f5.aarch64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.9.0+1531+a18208f5.x86_64.rpm", "python-PyMySQL-0:0.8.0-10.module+el8.9.0+1531+a18208f5.src.rpm", "python-pysocks-0:1.6.8-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-pytest-mock-0:1.9.0-4.module+el8.9.0+1531+a18208f5.src.rpm", "python-requests-0:2.20.0-4.module+el8.10.0+1817+0b01df83.src.rpm", "python-setuptools_scm-0:1.15.7-6.module+el8.9.0+1531+a18208f5.src.rpm", "python-sqlalchemy-0:1.3.2-2.module+el8.9.0+1531+a18208f5.src.rpm", "python-sqlalchemy-doc-0:1.3.2-2.module+el8.9.0+1531+a18208f5.noarch.rpm", "python-wheel-1:0.31.1-3.module+el8.9.0+1531+a18208f5.src.rpm", "python-wheel-1:0.31.1-3.module+el8.10.0+1910+234ad790.src.rpm", "pytz-0:2017.2-13.module+el8.10.0+1817+0b01df83.src.rpm", "PyYAML-0:3.12-16.module+el8.9.0+1531+a18208f5.src.rpm", "PyYAML-debugsource-0:3.12-16.module+el8.9.0+1531+a18208f5.aarch64.rpm", "PyYAML-debugsource-0:3.12-16.module+el8.9.0+1531+a18208f5.x86_64.rpm", "scipy-0:1.0.0-22.module+el8.10.0+1817+0b01df83.src.rpm", "scipy-debugsource-0:1.0.0-22.module+el8.10.0+1817+0b01df83.aarch64.rpm", "scipy-debugsource-0:1.0.0-22.module+el8.10.0+1817+0b01df83.x86_64.rpm", "python-docutils-0:0.14-12.module+el8.10.0+1592+61442852.src.rpm", "python-nose-0:1.3.7-31.module+el8.10.0+1592+61442852.src.rpm", "python-nose-docs-0:1.3.7-31.module+el8.10.0+1592+61442852.noarch.rpm", "python-pygments-0:2.2.0-22.module+el8.10.0+1592+61442852.src.rpm","python-pymongo-0:3.7.0-1.module+el8.10.0+1910+234ad790.src.rpm", "python-pymongo-0:3.7.0-1.module+el8.10.0+1592+61442852.src.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.10.0+1592+61442852.aarch64.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.10.0+1910+234ad790.aarch64.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.10.0+1910+234ad790.x86_64.rpm", "python-pymongo-debuginfo-0:3.7.0-1.module+el8.10.0+1592+61442852.x86_64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.10.0+1592+61442852.aarch64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.10.0+1910+234ad790.aarch64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.10.0+1592+61442852.x86_64.rpm", "python-pymongo-debugsource-0:3.7.0-1.module+el8.10.0+1910+234ad790.x86_64.rpm", "python-virtualenv-0:15.1.0-22.module+el8.10.0+1592+61442852.src.rpm", "python-wheel-1:0.31.1-3.module+el8.10.0+1592+61442852.src.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate security advisory for python27 on Rocky Linux 8. This update fixes a significant bug and ensures better performance.. Rocky Linux Security python27 update moderate. . LinuxSecurity.com Team
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-8446 http://linux.oracle.com/errata/ELSA-2024-8446.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: python-unversioned-command-3.9.18-3.el9_4.6.noarch.rpm python3-3.9.18-3.el9_4.6.x86_64.rpm python3-devel-3.9.18-3.el9_4.6.i686.rpm python3-devel-3.9.18-3.el9_4.6.x86_64.rpm python3-libs-3.9.18-3.el9_4.6.i686.rpm python3-libs-3.9.18-3.el9_4.6.x86_64.rpm python3-tkinter-3.9.18-3.el9_4.6.x86_64.rpm python3-3.9.18-3.el9_4.6.i686.rpm python3-debug-3.9.18-3.el9_4.6.i686.rpm python3-debug-3.9.18-3.el9_4.6.x86_64.rpm python3-idle-3.9.18-3.el9_4.6.i686.rpm python3-idle-3.9.18-3.el9_4.6.x86_64.rpm python3-test-3.9.18-3.el9_4.6.i686.rpm python3-test-3.9.18-3.el9_4.6.x86_64.rpm python3-tkinter-3.9.18-3.el9_4.6.i686.rpm aarch64: python-unversioned-command-3.9.18-3.el9_4.6.noarch.rpm python3-3.9.18-3.el9_4.6.aarch64.rpm python3-devel-3.9.18-3.el9_4.6.aarch64.rpm python3-libs-3.9.18-3.el9_4.6.aarch64.rpm python3-tkinter-3.9.18-3.el9_4.6.aarch64.rpm python3-debug-3.9.18-3.el9_4.6.aarch64.rpm python3-idle-3.9.18-3.el9_4.6.aarch64.rpm python3-test-3.9.18-3.el9_4.6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//python3.9-3.9.18-3.el9_4.6.src.rpm Related CVEs: CVE-2024-6232 Description of changes: [3.9.18-3.6] - Fix: CVE-2024-6232 - Resolves: RHEL-57421 _______________________________________________ El-errata mailing list
* bsc#1210638 Cross-References: * CVE-2023-27043 . # Security update for python Announcement ID: SUSE-SU-2024:0437-1 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-437=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-437=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-437=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-437=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * python-debuginfo-2.7.18-33.29.1 * python-tk-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-2.7.18-33.29.1 * python-gdbm-2.7.18-33.29.1 * python-curses-debuginfo-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 * python-base-debuginfo-2.7.18-33.29.1 * python-gdbm-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-2.7.18-33.29.1 * python-demo-2.7.18-33.29.1 *python-tk-2.7.18-33.29.1 * python-debugsource-2.7.18-33.29.1 * python-xml-2.7.18-33.29.1 * python-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-xml-debuginfo-2.7.18-33.29.1 * python-base-2.7.18-33.29.1 * python-curses-2.7.18-33.29.1 * python-idle-2.7.18-33.29.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch) * python-doc-2.7.18-33.29.1 * python-doc-pdf-2.7.18-33.29.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * python-base-32bit-2.7.18-33.29.1 * python-base-debuginfo-32bit-2.7.18-33.29.1 * libpython2_7-1_0-32bit-2.7.18-33.29.1 * python-debuginfo-32bit-2.7.18-33.29.1 * python-32bit-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-32bit-2.7.18-33.29.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * python-debuginfo-2.7.18-33.29.1 * python-tk-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-2.7.18-33.29.1 * python-gdbm-2.7.18-33.29.1 * python-curses-debuginfo-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 * python-base-debuginfo-2.7.18-33.29.1 * python-gdbm-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-2.7.18-33.29.1 * python-demo-2.7.18-33.29.1 * python-tk-2.7.18-33.29.1 * python-debugsource-2.7.18-33.29.1 * python-xml-2.7.18-33.29.1 * python-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-xml-debuginfo-2.7.18-33.29.1 * python-base-2.7.18-33.29.1 * python-curses-2.7.18-33.29.1 * python-idle-2.7.18-33.29.1 * SUSE Linux Enterprise Server 12 SP5 (noarch) * python-doc-2.7.18-33.29.1 * python-doc-pdf-2.7.18-33.29.1 * SUSE Linux Enterprise Server 12 SP5 (s390x x86_64) * python-base-32bit-2.7.18-33.29.1 * python-base-debuginfo-32bit-2.7.18-33.29.1 * libpython2_7-1_0-32bit-2.7.18-33.29.1 * python-debuginfo-32bit-2.7.18-33.29.1 * python-32bit-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-32bit-2.7.18-33.29.1 * SUSE Linux Enterprise Server for SAPApplications 12 SP5 (ppc64le x86_64) * python-debuginfo-2.7.18-33.29.1 * python-tk-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-2.7.18-33.29.1 * python-gdbm-2.7.18-33.29.1 * python-curses-debuginfo-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 * python-base-debuginfo-2.7.18-33.29.1 * python-gdbm-debuginfo-2.7.18-33.29.1 * python-xml-debuginfo-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-2.7.18-33.29.1 * python-demo-2.7.18-33.29.1 * python-tk-2.7.18-33.29.1 * python-xml-2.7.18-33.29.1 * python-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-debugsource-2.7.18-33.29.1 * python-base-2.7.18-33.29.1 * python-curses-2.7.18-33.29.1 * python-idle-2.7.18-33.29.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch) * python-doc-2.7.18-33.29.1 * python-doc-pdf-2.7.18-33.29.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (x86_64) * python-base-32bit-2.7.18-33.29.1 * python-base-debuginfo-32bit-2.7.18-33.29.1 * libpython2_7-1_0-32bit-2.7.18-33.29.1 * python-debuginfo-32bit-2.7.18-33.29.1 * python-32bit-2.7.18-33.29.1 * libpython2_7-1_0-debuginfo-32bit-2.7.18-33.29.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * python-base-debuginfo-2.7.18-33.29.1 * python-base-debugsource-2.7.18-33.29.1 * python-devel-2.7.18-33.29.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . This announcement highlights a significant enhancement for Java that focuses on CVE-2023-29015 concerning network security in multiple Fedora distributions.. Python Update, SUSE Security, Email Parsing Issues, Software Patch Update. . LinuxSecurity.com Team
* bsc#1210638 * bsc#1214685 * bsc#1214691 Cross-References: . # Security update for python Announcement ID: SUSE-SU-2023:4220-1 Rating: moderate References: * bsc#1210638 * bsc#1214685 * bsc#1214691 Cross-References: * CVE-2022-48565 * CVE-2022-48566 * CVE-2023-27043 CVSS scores: * CVE-2022-48565 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2022-48565 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-48566 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2022-48566 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP4 * SUSE Package Hub 15 15-SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python fixes the following issues: * CVE-2022-48566: Fixed a potential timing side channel due to inadequate checking during HMAC comparison (bsc#1214691). ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4220=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4220=1 * SUSE Package Hub 15 15-SP4 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-4220=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-4220=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4220=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-4220=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-4220=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * python-xml-2.7.18-150000.57.1 * python-demo-2.7.18-150000.57.1 * python-idle-2.7.18-150000.57.1 * python-tk-2.7.18-150000.57.1 * python-debuginfo-2.7.18-150000.57.1 * python-base-2.7.18-150000.57.1 * python-devel-2.7.18-150000.57.1 * python-curses-2.7.18-150000.57.1 * python-gdbm-2.7.18-150000.57.1 * python-gdbm-debuginfo-2.7.18-150000.57.1 * python-tk-debuginfo-2.7.18-150000.57.1 * python-base-debugsource-2.7.18-150000.57.1 * python-xml-debuginfo-2.7.18-150000.57.1 * python-debugsource-2.7.18-150000.57.1 * libpython2_7-1_0-2.7.18-150000.57.1 * python-curses-debuginfo-2.7.18-150000.57.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.57.1 * python-2.7.18-150000.57.1 * python-base-debuginfo-2.7.18-150000.57.1 * openSUSE Leap 15.4 (x86_64) * libpython2_7-1_0-32bit-2.7.18-150000.57.1 * python-32bit-debuginfo-2.7.18-150000.57.1 * python-base-32bit-debuginfo-2.7.18-150000.57.1 * libpython2_7-1_0-32bit-debuginfo-2.7.18-150000.57.1 * python-32bit-2.7.18-150000.57.1 *python-base-32bit-2.7.18-150000.57.1 * openSUSE Leap 15.4 (noarch) * python-doc-pdf-2.7.18-150000.57.1 * python-doc-2.7.18-150000.57.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python-xml-2.7.18-150000.57.1 * python-demo-2.7.18-150000.57.1 * python-idle-2.7.18-150000.57.1 * python-tk-2.7.18-150000.57.1 * python-debuginfo-2.7.18-150000.57.1 * python-base-2.7.18-150000.57.1 * python-devel-2.7.18-150000.57.1 * python-curses-2.7.18-150000.57.1 * python-gdbm-2.7.18-150000.57.1 * python-gdbm-debuginfo-2.7.18-150000.57.1 * python-tk-debuginfo-2.7.18-150000.57.1 * python-base-debugsource-2.7.18-150000.57.1 * python-xml-debuginfo-2.7.18-150000.57.1 * python-debugsource-2.7.18-150000.57.1 * libpython2_7-1_0-2.7.18-150000.57.1 * python-curses-debuginfo-2.7.18-150000.57.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.57.1 * python-2.7.18-150000.57.1 * python-base-debuginfo-2.7.18-150000.57.1 * openSUSE Leap 15.5 (x86_64) * libpython2_7-1_0-32bit-2.7.18-150000.57.1 * python-32bit-debuginfo-2.7.18-150000.57.1 * python-base-32bit-debuginfo-2.7.18-150000.57.1 * libpython2_7-1_0-32bit-debuginfo-2.7.18-150000.57.1 * python-32bit-2.7.18-150000.57.1 * python-base-32bit-2.7.18-150000.57.1 * openSUSE Leap 15.5 (noarch) * python-doc-pdf-2.7.18-150000.57.1 * python-doc-2.7.18-150000.57.1 * SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x x86_64) * python-base-debugsource-2.7.18-150000.57.1 * python-devel-2.7.18-150000.57.1 * python-base-debuginfo-2.7.18-150000.57.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * python-xml-2.7.18-150000.57.1 * python-debuginfo-2.7.18-150000.57.1 * python-base-2.7.18-150000.57.1 * python-devel-2.7.18-150000.57.1 * python-curses-2.7.18-150000.57.1 * python-gdbm-2.7.18-150000.57.1 * python-gdbm-debuginfo-2.7.18-150000.57.1 * python-base-debugsource-2.7.18-150000.57.1 * python-xml-debuginfo-2.7.18-150000.57.1 * python-debugsource-2.7.18-150000.57.1 * libpython2_7-1_0-2.7.18-150000.57.1 * python-curses-debuginfo-2.7.18-150000.57.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.57.1 * python-2.7.18-150000.57.1 * python-base-debuginfo-2.7.18-150000.57.1 * SUSE Manager Proxy 4.2 (x86_64) * python-debuginfo-2.7.18-150000.57.1 * python-base-2.7.18-150000.57.1 * python-base-debugsource-2.7.18-150000.57.1 * python-debugsource-2.7.18-150000.57.1 * libpython2_7-1_0-2.7.18-150000.57.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.57.1 * python-2.7.18-150000.57.1 * python-base-debuginfo-2.7.18-150000.57.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * python-debuginfo-2.7.18-150000.57.1 * python-base-2.7.18-150000.57.1 * python-base-debugsource-2.7.18-150000.57.1 * python-debugsource-2.7.18-150000.57.1 * libpython2_7-1_0-2.7.18-150000.57.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.57.1 * python-2.7.18-150000.57.1 * python-base-debuginfo-2.7.18-150000.57.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * python-xml-2.7.18-150000.57.1 * python-debuginfo-2.7.18-150000.57.1 * python-base-2.7.18-150000.57.1 * python-devel-2.7.18-150000.57.1 * python-curses-2.7.18-150000.57.1 * python-gdbm-2.7.18-150000.57.1 * python-gdbm-debuginfo-2.7.18-150000.57.1 * python-base-debugsource-2.7.18-150000.57.1 * python-xml-debuginfo-2.7.18-150000.57.1 * python-debugsource-2.7.18-150000.57.1 * libpython2_7-1_0-2.7.18-150000.57.1 * python-curses-debuginfo-2.7.18-150000.57.1 * libpython2_7-1_0-debuginfo-2.7.18-150000.57.1 * python-2.7.18-150000.57.1 * python-base-debuginfo-2.7.18-150000.57.1 ## References: * https://www.suse.com/security/cve/CVE-2022-48565.html * https://www.suse.com/security/cve/CVE-2022-48566.html * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 * https://bugzilla.suse.com/show_bug.cgi?id=1214685 *https://bugzilla.suse.com/show_bug.cgi?id=1214691 . An essential patch rollout for Python on SUSE tackles several security flaws to enhance system protection.. SUSE Python Update, OpenSUSE Security, Timing Issue Fix. . LinuxSecurity.com Team
An update for python3.11 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: python3.11 security update Advisory ID: RHSA-2023:5463-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5463 Issue date: 2023-10-05 CVE Names: CVE-2023-40217 ===================================================================== 1. Summary: An update for python3.11 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Enterprise Linux CRB (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: Python is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. Security Fix(es): * python: TLS handshake bypass (CVE-2023-40217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 2235789 - CVE-2023-40217 python: TLS handshake bypass 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: python3.11-3.11.2-2.el8_8.2.src.rpm aarch64: python3.11-3.11.2-2.el8_8.2.aarch64.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.aarch64.rpm python3.11-debugsource-3.11.2-2.el8_8.2.aarch64.rpm python3.11-devel-3.11.2-2.el8_8.2.aarch64.rpm python3.11-libs-3.11.2-2.el8_8.2.aarch64.rpm python3.11-tkinter-3.11.2-2.el8_8.2.aarch64.rpm noarch: python3.11-rpm-macros-3.11.2-2.el8_8.2.noarch.rpm ppc64le: python3.11-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-debugsource-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-devel-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-libs-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-tkinter-3.11.2-2.el8_8.2.ppc64le.rpm s390x: python3.11-3.11.2-2.el8_8.2.s390x.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.s390x.rpm python3.11-debugsource-3.11.2-2.el8_8.2.s390x.rpm python3.11-devel-3.11.2-2.el8_8.2.s390x.rpm python3.11-libs-3.11.2-2.el8_8.2.s390x.rpm python3.11-tkinter-3.11.2-2.el8_8.2.s390x.rpm x86_64: python3.11-3.11.2-2.el8_8.2.x86_64.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.i686.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.x86_64.rpm python3.11-debugsource-3.11.2-2.el8_8.2.i686.rpm python3.11-debugsource-3.11.2-2.el8_8.2.x86_64.rpm python3.11-devel-3.11.2-2.el8_8.2.i686.rpm python3.11-devel-3.11.2-2.el8_8.2.x86_64.rpm python3.11-libs-3.11.2-2.el8_8.2.i686.rpm python3.11-libs-3.11.2-2.el8_8.2.x86_64.rpm python3.11-tkinter-3.11.2-2.el8_8.2.x86_64.rpm Red Hat Enterprise Linux CRB (v.8): aarch64: python3.11-debug-3.11.2-2.el8_8.2.aarch64.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.aarch64.rpm python3.11-debugsource-3.11.2-2.el8_8.2.aarch64.rpm python3.11-idle-3.11.2-2.el8_8.2.aarch64.rpm python3.11-test-3.11.2-2.el8_8.2.aarch64.rpm ppc64le: python3.11-debug-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-debugsource-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-idle-3.11.2-2.el8_8.2.ppc64le.rpm python3.11-test-3.11.2-2.el8_8.2.ppc64le.rpm s390x: python3.11-debug-3.11.2-2.el8_8.2.s390x.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.s390x.rpm python3.11-debugsource-3.11.2-2.el8_8.2.s390x.rpm python3.11-idle-3.11.2-2.el8_8.2.s390x.rpm python3.11-test-3.11.2-2.el8_8.2.s390x.rpm x86_64: python3.11-3.11.2-2.el8_8.2.i686.rpm python3.11-debug-3.11.2-2.el8_8.2.i686.rpm python3.11-debug-3.11.2-2.el8_8.2.x86_64.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.i686.rpm python3.11-debuginfo-3.11.2-2.el8_8.2.x86_64.rpm python3.11-debugsource-3.11.2-2.el8_8.2.i686.rpm python3.11-debugsource-3.11.2-2.el8_8.2.x86_64.rpm python3.11-idle-3.11.2-2.el8_8.2.i686.rpm python3.11-idle-3.11.2-2.el8_8.2.x86_64.rpm python3.11-test-3.11.2-2.el8_8.2.i686.rpm python3.11-test-3.11.2-2.el8_8.2.x86_64.rpm python3.11-tkinter-3.11.2-2.el8_8.2.i686.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-40217 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJlHtXQAAoJENzjgjWX9erEOhsP/ReoNfsCP0hmC7S3cjL6i8Lj Ts3DyJiC3CXlMxxNUFkh27nnqSIRvSXxb/dEu/D7+zDDw7cpecXUqNA5pvikTDcj iAGVhLygOLtqzYuEqtX1BxOydIsP4jEK8e3PTs/TzgNmIhBqwoOWk/q7MCe84m1+ DMoK38WHWmpIQAuQy+icogCy3PLqXuvCzeKcQPYEiyoBfT9a6xJ5EiCEGsJzSOkx G5GoSfnLniUsBpWsXvz6bW9eJxSAmZ5Sv2UY4m0aHbTkEv/Tc+VBlR+wQoOQBIcy HHoXmhDSh8OzJejzyyupP6JB6R7NqKfEg/LG7xuD6k3c4nBYAPcvcyl/fijSAmw4 qs8S4Waeee50T8cODB5PSwkSZwVhfCuF3o9OpciXRbWwO/4cGgM2p7vFfeH57cGT hbFkXGA/4B3kVZChLuFQH/TpBtDH2VDCDlo5ct9hszZSkU9HuXkClVxscUWVB6VK UkTxgKaK6tzuQwJaWq+xXif3jGULtDbqCbWVKPb/Omp4nFlMYDwJBaW5gLkzwAK/ DcD9uTOv1HosLlTT9aj6pbb70Bu5JMyEmSla7pzFCStbgh6EFIodhnF1i3GrNrZd RODlCuY3h5YXGpzMNxjTzFvkyWMbnlvpdDi8mzTIHi0z22Jd9BcNLNd27Q5HOraT 48GSuHvaS3JTTfyBwjlE =uuGk -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-3555 https://linux.oracle.com/errata/ELSA-2023-3555.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: python-2.7.5-93.0.1.el7_9.x86_64.rpm python-debug-2.7.5-93.0.1.el7_9.x86_64.rpm python-devel-2.7.5-93.0.1.el7_9.x86_64.rpm python-libs-2.7.5-93.0.1.el7_9.i686.rpm python-libs-2.7.5-93.0.1.el7_9.x86_64.rpm python-test-2.7.5-93.0.1.el7_9.x86_64.rpm python-tools-2.7.5-93.0.1.el7_9.x86_64.rpm tkinter-2.7.5-93.0.1.el7_9.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//python-2.7.5-93.0.1.el7_9.src.rpm Related CVEs: CVE-2023-24329 Description of changes: [2.7.5-93.0.1] - Add Oracle Linux distribution in platform.py [orabug 20812544] [2.7.5-93] - Fix for CVE-2023-24329 Resolves: rhbz#2173917 _______________________________________________ El-errata mailing list
An update that solves one vulnerability, contains two features and has 6 fixes is now available. . openSUSE Security Update: Security update for aws-cli, python-boto3, python-botocore, python-service_identity, python-trustme, python-urllib3 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2817-1 Rating: moderate References: #1102408 #1138715 #1138746 #1176389 #1177120 #1182421 #1182422 ECO-3352 PM-2485 Cross-References: CVE-2020-26137 CVSS scores: CVE-2020-26137 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVE-2020-26137 (SUSE): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves one vulnerability, contains two features and has 6 fixes is now available. Description: This patch updates the Python AWS SDK stack in SLE 15: General: # aws-cli - Version updated to upstream release v1.19.9 For a detailed list of all changes, please refer to the changelog file of this package. # python-boto3 - Version updated to upstream release 1.17.9 For a detailed list of all changes, please refer to the changelog file of this package. # python-botocore - Version updated to upstream release 1.20.9 For a detailed list of all changes, please refer to the changelog file of this package. # python-urllib3 - Version updated to upstream release 1.25.10 For a detailed list of all changes, please refer to the changelog file of this package. # python-service_identity - Added this new package to resolve runtime dependencies for other packages. Version: 18.1.0 # python-trustme - Added this new package to resolve runtime dependencies for other packages. Version: 0.6.0 Security fixes: # python-urllib3: - CVE-2020-26137:urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest() (bsc#1177120) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2817=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): python-cffi-debuginfo-1.13.2-3.2.5 python-cffi-debugsource-1.13.2-3.2.5 python-cryptography-debuginfo-2.8-10.1 python-cryptography-debugsource-2.8-10.1 python2-cffi-1.13.2-3.2.5 python2-cffi-debuginfo-1.13.2-3.2.5 python2-cryptography-2.8-10.1 python2-cryptography-debuginfo-2.8-10.1 python3-cffi-1.13.2-3.2.5 python3-cffi-debuginfo-1.13.2-3.2.5 python3-cryptography-2.8-10.1 python3-cryptography-debuginfo-2.8-10.1 - openSUSE Leap 15.3 (noarch): aws-cli-1.19.9-26.1 python2-asn1crypto-0.24.0-3.2.1 python2-boto3-1.17.9-19.1 python2-botocore-1.20.9-33.1 python2-pyasn1-0.4.2-3.2.1 python2-pycparser-2.17-3.2.1 python2-urllib3-1.25.10-9.14.1 python3-asn1crypto-0.24.0-3.2.1 python3-boto3-1.17.9-19.1 python3-botocore-1.20.9-33.1 python3-pyasn1-0.4.2-3.2.1 python3-pycparser-2.17-3.2.1 References: https://www.suse.com/security/cve/CVE-2020-26137.html https://bugzilla.suse.com/1102408 https://bugzilla.suse.com/1138715 https://bugzilla.suse.com/1138746 https://bugzilla.suse.com/1176389 https://bugzilla.suse.com/1177120 https://bugzilla.suse.com/1182421 https://bugzilla.suse.com/1182422 . An important announcement for Fedora patching a significant SQL injection vulnerability in Ruby libraries, enhancing overall platform integrity.. openSUSE Update, PythonSecurity Fixes, AWS-CLI Patch. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3597-1 Rating: important References: #1176262 Cross-References: CVE-2019-20916 Affected Products: SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Module for Python2 15-SP3 SUSE Linux Enterprise Module for Python2 15-SP2 SUSE Linux Enterprise Module for Python2 15-SP1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 SUSE Linux Enterprise Module for Desktop Applications 15-SP2 SUSE Linux Enterprise Module for Desktop Applications 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP1 SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python fixes the following issues: - Fixed a directory traversal in _download_http_url() (bsc#1176262 CVE-2019-20916) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2020-3597=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2020-3597=1 - SUSE LinuxEnterprise Module for Python2 15-SP3: zypper in -t patch SUSE-SLE-Module-Python2-15-SP3-2020-3597=1 - SUSE Linux Enterprise Module for Python2 15-SP2: zypper in -t patch SUSE-SLE-Module-Python2-15-SP2-2020-3597=1 - SUSE Linux Enterprise Module for Python2 15-SP1: zypper in -t patch SUSE-SLE-Module-Python2-15-SP1-2020-3597=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP3-2020-3597=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP2-2020-3597=1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP1-2020-3597=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2020-3597=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-3597=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-3597=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2020-3597=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2020-3597=1 Package List: - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): libpython2_7-1_0-2.7.17-7.47.1 libpython2_7-1_0-debuginfo-2.7.17-7.47.1 python-2.7.17-7.47.1 python-base-2.7.17-7.47.1 python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-curses-2.7.17-7.47.1 python-curses-debuginfo-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-devel-2.7.17-7.47.1 python-gdbm-2.7.17-7.47.1 python-gdbm-debuginfo-2.7.17-7.47.1 python-xml-2.7.17-7.47.1 python-xml-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): libpython2_7-1_0-2.7.17-7.47.1 libpython2_7-1_0-debuginfo-2.7.17-7.47.1 python-2.7.17-7.47.1 python-base-2.7.17-7.47.1 python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-curses-2.7.17-7.47.1 python-curses-debuginfo-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-devel-2.7.17-7.47.1 python-gdbm-2.7.17-7.47.1 python-gdbm-debuginfo-2.7.17-7.47.1 python-xml-2.7.17-7.47.1 python-xml-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Python2 15-SP3 (aarch64 ppc64le s390x x86_64): python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-curses-2.7.17-7.47.1 python-curses-debuginfo-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-devel-2.7.17-7.47.1 python-gdbm-2.7.17-7.47.1 python-gdbm-debuginfo-2.7.17-7.47.1 python-xml-2.7.17-7.47.1 python-xml-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Python2 15-SP2 (aarch64 ppc64le s390x x86_64): python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-curses-2.7.17-7.47.1 python-curses-debuginfo-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-devel-2.7.17-7.47.1 python-gdbm-2.7.17-7.47.1 python-gdbm-debuginfo-2.7.17-7.47.1 python-xml-2.7.17-7.47.1 python-xml-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Python2 15-SP1 (aarch64 ppc64le s390x x86_64): python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-curses-2.7.17-7.47.1 python-curses-debuginfo-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-devel-2.7.17-7.47.1 python-gdbm-2.7.17-7.47.1 python-gdbm-debuginfo-2.7.17-7.47.1 python-xml-2.7.17-7.47.1 python-xml-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (aarch64 ppc64le s390x x86_64): python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-tk-2.7.17-7.47.1 python-tk-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP2 (aarch64 ppc64le s390x x86_64): python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-tk-2.7.17-7.47.1 python-tk-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Desktop Applications 15-SP1 (aarch64 ppc64le s390x x86_64): python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-tk-2.7.17-7.47.1 python-tk-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): libpython2_7-1_0-2.7.17-7.47.1 libpython2_7-1_0-debuginfo-2.7.17-7.47.1 python-2.7.17-7.47.1 python-base-2.7.17-7.47.1 python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libpython2_7-1_0-2.7.17-7.47.1 libpython2_7-1_0-debuginfo-2.7.17-7.47.1 python-2.7.17-7.47.1 python-base-2.7.17-7.47.1 python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libpython2_7-1_0-2.7.17-7.47.1 libpython2_7-1_0-debuginfo-2.7.17-7.47.1 python-2.7.17-7.47.1 python-base-2.7.17-7.47.1 python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): libpython2_7-1_0-2.7.17-7.47.1 libpython2_7-1_0-debuginfo-2.7.17-7.47.1 python-2.7.17-7.47.1 python-base-2.7.17-7.47.1 python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-curses-2.7.17-7.47.1 python-curses-debuginfo-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-devel-2.7.17-7.47.1 python-gdbm-2.7.17-7.47.1 python-gdbm-debuginfo-2.7.17-7.47.1 python-xml-2.7.17-7.47.1 python-xml-debuginfo-2.7.17-7.47.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): libpython2_7-1_0-2.7.17-7.47.1 libpython2_7-1_0-debuginfo-2.7.17-7.47.1 python-2.7.17-7.47.1 python-base-2.7.17-7.47.1 python-base-debuginfo-2.7.17-7.47.1 python-base-debugsource-2.7.17-7.47.1 python-curses-2.7.17-7.47.1 python-curses-debuginfo-2.7.17-7.47.1 python-debuginfo-2.7.17-7.47.1 python-debugsource-2.7.17-7.47.1 python-devel-2.7.17-7.47.1 python-gdbm-2.7.17-7.47.1 python-gdbm-debuginfo-2.7.17-7.47.1 python-xml-2.7.17-7.47.1 python-xml-debuginfo-2.7.17-7.47.1 References: https://www.suse.com/security/cve/CVE-2019-20916.html https://bugzilla.suse.com/1176262 . SUSE has released an important security patch for Python that addresses a directory traversal flaw. Please apply it without delay.. SUSE Python Update, Security Patch, Critical Issues, Directory Traversal Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.