Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
100

SUSE: 2025:01744-1 important: python313-setuptools path issue

* bsc#1243313 Cross-References: * CVE-2025-47273 . # Security update for python313-setuptools Announcement ID: SUSE-SU-2025:01744-1 Release Date: 2025-05-29T11:48:52Z Rating: important References: * bsc#1243313 Cross-References: * CVE-2025-47273 CVSS scores: * CVE-2025-47273 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-47273 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-47273 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python313-setuptools fixes the following issues: * CVE-2025-47273: path traversal in PackageIndex.download may lead to an arbitrary file write (bsc#1243313). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2025-1744=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python313-setuptools-72.1.0-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47273.html * https://bugzilla.suse.com/show_bug.cgi?id=1243313 . An important update for python313-setuptools mitigates a directory traversal vulnerability in SUSE Linux, reinforcing system protection.. python313-setuptools, SUSE update, path traversal risk, security patch, Linux security. . Severity: Important.LinuxSecurity.com Team

Calendar%202 May 29, 2025 Important SuSE
202

openSUSE: 2025:01649-1 important: python-tornado6 denial of service

An update that solves one vulnerability can now be installed.. # Security update for python-tornado6 Announcement ID: SUSE-SU-2025:01649-1 Release Date: 2025-05-22T07:45:14Z Rating: important References: * bsc#1243268 Cross-References: * CVE-2025-47287 CVSS scores: * CVE-2025-47287 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47287 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47287 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for python-tornado6 fixes the following issues: * CVE-2025-47287: excessive logging when parsing malformed `multipart/form- data` can lead to a denial-of-service (bsc#1243268). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-1649=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1649=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2025-1649=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-1649=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-1649=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-1649=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-1649=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-1649=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-1649=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-1649=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-1649=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * Python 3 Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 *python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-tornado6-6.3.2-150400.9.9.1 * python311-tornado6-debuginfo-6.3.2-150400.9.9.1 * python-tornado6-debugsource-6.3.2-150400.9.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-47287.html * https://bugzilla.suse.com/show_bug.cgi?id=1243268 . Critical news for python-tornado6 addresses service disruption vulnerabilities in specific SUSE versions. Implement updates immediately.. python-tornado6 update, SUSE security advisory, denial of service fix, important patches, security updatenotice. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2025 Important OpenSUSE
219

Rocky Linux 8 RLSA-2024:8359 moderate: python39 security fix

Moderate: python39:3.9 and python39-devel:3.9 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:8359", "synopsis": "Moderate: python39:3.9 and python39-devel:3.9 security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.python-iniconfig, module.python-packaging, python-py, python-requests, module.pytest, module.python39, python-wheel, Cython, python3x-six, python39, numpy, python-chardet, pytest, module.python-attrs, pybind11, module.python-ply, module.python-requests, module.python-cffi, module.pybind11, python-psycopg2, PyYAML, module.python3x-setuptools, python-pycparser, module.PyYAML, module.python-cryptography, python-lxml, python-more-itertools, module.python-idna, module.scipy, module.numpy, python-wcwidth, module.python3x-pyparsing, module.python-PyMySQL, python-PyMySQL, python3x-pyparsing, python3x-setuptools, module.python-urllib3, module.python-toml, python-toml, module.python-wheel, python-pysocks, module.mod_wsgi, module.python3x-pip, module.python-pycparser, python-idna, module.python-wcwidth, python-pluggy, module.python-py, python-packaging, python-urllib3, python-cffi, python-iniconfig, module.python-psutil, python-ply, module.python-pysocks, python-psutil, python-attrs, python3x-pip, mod_wsgi, scipy, module.python-lxml, module.python-pluggy, module.python-more-itertools, module.python-psycopg2, module.Cython, module.python-chardet, module.python3x-six, python-cryptography.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.\n\nSecurity Fix(es):\n\n* python: cpython: tarfile: ReDos via excessivebacktracking while parsing header values (CVE-2024-6232)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2309426", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2309426", "description": ""}], "cves": [{"name": "CVE-2024-6232", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-6232", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-10-25T17:16:21.716473Z", "rpms": {"Rocky Linux 8": {"nvras": ["Cython-0:0.29.21-5.module+el8.10.0+1582+bc278001.src.rpm", "Cython-debugsource-0:0.29.21-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "Cython-debugsource-0:0.29.21-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "mod_wsgi-0:4.7.1-7.module+el8.10.0+1582+bc278001.src.rpm", "numpy-0:1.19.4-3.module+el8.10.0+1582+bc278001.src.rpm", "numpy-debugsource-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "numpy-debugsource-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "pybind11-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.src.rpm", "pytest-0:6.0.2-2.module+el8.10.0+1582+bc278001.src.rpm", "python39-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.src.rpm", "python39-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-attrs-0:20.3.0-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-cffi-0:1.14.3-2.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-cffi-0:1.14.3-2.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-cffi-debuginfo-0:1.14.3-2.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-cffi-debuginfo-0:1.14.3-2.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-chardet-0:3.0.4-19.module+el8.10.0+1582+bc278001.noarch.rpm","python39-cryptography-0:3.3.1-3.module+el8.10.0+1697+7e517775.aarch64.rpm", "python39-cryptography-0:3.3.1-3.module+el8.10.0+1697+7e517775.x86_64.rpm", "python39-cryptography-debuginfo-0:3.3.1-3.module+el8.10.0+1697+7e517775.aarch64.rpm", "python39-cryptography-debuginfo-0:3.3.1-3.module+el8.10.0+1697+7e517775.x86_64.rpm", "python39-Cython-0:0.29.21-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-Cython-0:0.29.21-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-Cython-debuginfo-0:0.29.21-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-Cython-debuginfo-0:0.29.21-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-debug-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-debug-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-debuginfo-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-debuginfo-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-debugsource-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-debugsource-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-devel-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-devel-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-idle-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-idle-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-idna-0:2.10-4.module+el8.10.0+1809+41195054.noarch.rpm", "python39-iniconfig-0:1.1.1-2.module+el8.9.0+1332+dd574197.noarch.rpm", "python39-libs-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-libs-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-lxml-0:4.6.5-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-lxml-0:4.6.5-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-lxml-debuginfo-0:4.6.5-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-lxml-debuginfo-0:4.6.5-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-mod_wsgi-0:4.7.1-7.module+el8.10.0+1582+bc278001.aarch64.rpm","python39-mod_wsgi-0:4.7.1-7.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-more-itertools-0:8.5.0-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-numpy-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-numpy-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-numpy-debuginfo-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-numpy-debuginfo-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-numpy-doc-0:1.19.4-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-numpy-f2py-0:1.19.4-3.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-numpy-f2py-0:1.19.4-3.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-packaging-0:20.4-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pip-0:20.2.4-9.module+el8.10.0+1721+e52d6351.noarch.rpm", "python39-pip-wheel-0:20.2.4-9.module+el8.10.0+1721+e52d6351.noarch.rpm", "python39-pluggy-0:0.13.1-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-ply-0:3.11-10.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-psutil-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-psutil-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-psutil-debuginfo-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-psutil-debuginfo-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-psycopg2-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.aarch64.rpm", "python39-psycopg2-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.x86_64.rpm", "python39-psycopg2-debuginfo-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.aarch64.rpm", "python39-psycopg2-debuginfo-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.x86_64.rpm", "python39-psycopg2-doc-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.aarch64.rpm", "python39-psycopg2-doc-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.x86_64.rpm", "python39-psycopg2-tests-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.aarch64.rpm", "python39-psycopg2-tests-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.x86_64.rpm", "python39-py-0:1.10.0-1.module+el8.10.0+1582+bc278001.noarch.rpm","python39-pybind11-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-pybind11-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-pybind11-devel-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python39-pybind11-devel-0:2.7.1-1.module+el8.9.0+1357+a3b80af7.x86_64.rpm", "python39-pycparser-0:2.20-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-PyMySQL-0:0.10.1-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pyparsing-0:2.4.7-5.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pysocks-0:1.7.1-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pytest-0:6.0.2-2.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-pyyaml-0:5.4.1-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-pyyaml-0:5.4.1-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-pyyaml-debuginfo-0:5.4.1-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-pyyaml-debuginfo-0:5.4.1-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-requests-0:2.25.0-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-rpm-macros-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.noarch.rpm", "python39-scipy-0:1.5.4-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-scipy-0:1.5.4-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-scipy-debuginfo-0:1.5.4-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "python39-scipy-debuginfo-0:1.5.4-5.module+el8.10.0+1582+bc278001.x86_64.rpm", "python39-setuptools-0:50.3.2-6.module+el8.10.0+1861+0f5e39ec.noarch.rpm", "python39-setuptools-wheel-0:50.3.2-6.module+el8.10.0+1861+0f5e39ec.noarch.rpm", "python39-six-0:1.15.0-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-test-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-test-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-tkinter-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.aarch64.rpm", "python39-tkinter-0:3.9.20-1.module+el8.10.0+1876+829fd4e0.x86_64.rpm", "python39-toml-0:0.10.1-5.module+el8.9.0+1332+dd574197.noarch.rpm","python39-urllib3-0:1.25.10-5.module+el8.10.0+1545+03246da9.noarch.rpm", "python39-wcwidth-0:0.2.5-3.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-wheel-1:0.35.1-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python39-wheel-wheel-1:0.35.1-4.module+el8.10.0+1582+bc278001.noarch.rpm", "python3x-pip-0:20.2.4-9.module+el8.10.0+1721+e52d6351.src.rpm", "python3x-pyparsing-0:2.4.7-5.module+el8.10.0+1582+bc278001.src.rpm", "python3x-setuptools-0:50.3.2-6.module+el8.10.0+1861+0f5e39ec.src.rpm", "python3x-six-0:1.15.0-3.module+el8.10.0+1582+bc278001.src.rpm", "python-attrs-0:20.3.0-2.module+el8.10.0+1582+bc278001.src.rpm", "python-cffi-0:1.14.3-2.module+el8.10.0+1582+bc278001.src.rpm", "python-cffi-debugsource-0:1.14.3-2.module+el8.10.0+1582+bc278001.aarch64.rpm", "python-cffi-debugsource-0:1.14.3-2.module+el8.10.0+1582+bc278001.x86_64.rpm", "python-chardet-0:3.0.4-19.module+el8.10.0+1582+bc278001.src.rpm", "python-cryptography-0:3.3.1-3.module+el8.10.0+1697+7e517775.src.rpm", "python-cryptography-debugsource-0:3.3.1-3.module+el8.10.0+1697+7e517775.aarch64.rpm", "python-cryptography-debugsource-0:3.3.1-3.module+el8.10.0+1697+7e517775.x86_64.rpm", "python-idna-0:2.10-4.module+el8.10.0+1809+41195054.src.rpm", "python-iniconfig-0:1.1.1-2.module+el8.9.0+1332+dd574197.src.rpm", "python-lxml-0:4.6.5-1.module+el8.10.0+1582+bc278001.src.rpm", "python-lxml-debugsource-0:4.6.5-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "python-lxml-debugsource-0:4.6.5-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "python-more-itertools-0:8.5.0-2.module+el8.10.0+1582+bc278001.src.rpm", "python-packaging-0:20.4-4.module+el8.10.0+1582+bc278001.src.rpm", "python-pluggy-0:0.13.1-3.module+el8.10.0+1582+bc278001.src.rpm", "python-ply-0:3.11-10.module+el8.10.0+1582+bc278001.src.rpm", "python-psutil-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.src.rpm", "python-psutil-debugsource-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.aarch64.rpm", "python-psutil-debugsource-0:5.8.0-4.module+el8.9.0+1357+a3b80af7.x86_64.rpm","python-psycopg2-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.src.rpm", "python-psycopg2-debugsource-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.aarch64.rpm", "python-psycopg2-debugsource-0:2.8.6-3.module+el8.10.0+1660+b5b6f004.x86_64.rpm", "python-py-0:1.10.0-1.module+el8.10.0+1582+bc278001.src.rpm", "python-pycparser-0:2.20-3.module+el8.10.0+1582+bc278001.src.rpm", "python-PyMySQL-0:0.10.1-2.module+el8.10.0+1582+bc278001.src.rpm", "python-pysocks-0:1.7.1-4.module+el8.10.0+1582+bc278001.src.rpm", "python-requests-0:2.25.0-3.module+el8.10.0+1582+bc278001.src.rpm", "python-toml-0:0.10.1-5.module+el8.9.0+1332+dd574197.src.rpm", "python-urllib3-0:1.25.10-5.module+el8.10.0+1545+03246da9.src.rpm", "python-wcwidth-0:0.2.5-3.module+el8.10.0+1582+bc278001.src.rpm", "python-wheel-1:0.35.1-4.module+el8.10.0+1582+bc278001.src.rpm", "PyYAML-0:5.4.1-1.module+el8.10.0+1582+bc278001.src.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.10.0+1582+bc278001.aarch64.rpm", "PyYAML-debugsource-0:5.4.1-1.module+el8.10.0+1582+bc278001.x86_64.rpm", "scipy-0:1.5.4-5.module+el8.10.0+1582+bc278001.src.rpm", "scipy-debugsource-0:1.5.4-5.module+el8.10.0+1582+bc278001.aarch64.rpm", "scipy-debugsource-0:1.5.4-5.module+el8.10.0+1582+bc278001.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. AlmaLinux provides an essential security update for python38 and python38-devel targeting notable weaknesses.. python39 updates, Rocky Linux security, python security advisory. . LinuxSecurity.com Team

Calendar%202 Oct 25, 2024 Rocky Linux
100

SUSE: 2024:2904-1 Important: Python312-Setuptools Code Execution

* bsc#1228105 Cross-References: * CVE-2024-6345 . # Security update for python312-setuptools Announcement ID: SUSE-SU-2024:2904-1 Rating: important References: * bsc#1228105 Cross-References: * CVE-2024-6345 CVSS scores: * CVE-2024-6345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for python312-setuptools fixes the following issues: * CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-2904=1 openSUSE-SLE-15.6-2024-2904=1 * Python 3 Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Python3-15-SP6-2024-2904=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python312-setuptools-68.1.2-150600.3.3.1 * Python 3 Module 15-SP6 (noarch) * python312-setuptools-68.1.2-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6345.html * https://bugzilla.suse.com/show_bug.cgi?id=1228105 . Crucial python312-setuptools enhancement tackles critical code execution vulnerabilities. Utilize suggested installation procedures immediately.. python312-setuptools, security update, openSUSE, SUSE Linux, code execution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 14, 2024 Important SuSE
100

openSUSE 15.4 & 15.5: 2024:0782-1 Important: Python311 Expat Bug

* bsc#1196025 * bsc#1210638 * bsc#1219666 Cross-References: . # Security update for python311 Announcement ID: SUSE-SU-2024:0782-1 Rating: important References: * bsc#1196025 * bsc#1210638 * bsc#1219666 Cross-References: * CVE-2022-25236 * CVE-2023-27043 * CVE-2023-6597 CVSS scores: * CVE-2022-25236 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2022-25236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-6597 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Python 3 Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2023-6597: Fixed symlink bug in cleanup of tempfile.TemporaryDirectory (bsc#1219666). * CVE-2023-27043: Fixed incorrect e-mqil parsing (bsc#1210638). * CVE-2022-25236: Fixed an expat vulnerability by supporting expat > = 2.4.4 (bsc#1212015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-782=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-782=1 * Python 3 Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2024-782=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-782=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-782=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-782=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-782=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-782=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 * python311-testsuite-debuginfo-3.11.8-150400.9.23.1 * python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-debugsource-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-testsuite-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * openSUSE Leap 15.4 (x86_64) * libpython3_11-1_0-32bit-3.11.8-150400.9.23.1 *python311-base-32bit-3.11.8-150400.9.23.1 * libpython3_11-1_0-32bit-debuginfo-3.11.8-150400.9.23.1 * python311-32bit-debuginfo-3.11.8-150400.9.23.1 * python311-base-32bit-debuginfo-3.11.8-150400.9.23.1 * python311-32bit-3.11.8-150400.9.23.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_11-1_0-64bit-3.11.8-150400.9.23.1 * libpython3_11-1_0-64bit-debuginfo-3.11.8-150400.9.23.1 * python311-base-64bit-3.11.8-150400.9.23.1 * python311-64bit-debuginfo-3.11.8-150400.9.23.1 * python311-base-64bit-debuginfo-3.11.8-150400.9.23.1 * python311-64bit-3.11.8-150400.9.23.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 * python311-testsuite-debuginfo-3.11.8-150400.9.23.1 * python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-debugsource-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-testsuite-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * openSUSE Leap 15.5 (x86_64) * libpython3_11-1_0-32bit-3.11.8-150400.9.23.1 * python311-base-32bit-3.11.8-150400.9.23.1 * libpython3_11-1_0-32bit-debuginfo-3.11.8-150400.9.23.1 * python311-32bit-debuginfo-3.11.8-150400.9.23.1 * python311-base-32bit-debuginfo-3.11.8-150400.9.23.1 * python311-32bit-3.11.8-150400.9.23.1 * Python 3 Module 15-SP5 (aarch64 ppc64le s390xx86_64) * python311-debuginfo-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 * python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 * python311-debugsource-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-debuginfo-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 * python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 * python311-debugsource-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-debuginfo-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 *python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 * python311-debugsource-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (x86_64) * python311-debuginfo-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 * python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 * python311-debugsource-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-debuginfo-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 * python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 *python311-debugsource-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-debuginfo-3.11.8-150400.9.23.1 * python311-base-debuginfo-3.11.8-150400.9.23.1 * python311-tools-3.11.8-150400.9.23.1 * python311-doc-3.11.8-150400.9.23.1 * python311-dbm-debuginfo-3.11.8-150400.9.23.1 * python311-debugsource-3.11.8-150400.9.23.1 * python311-doc-devhelp-3.11.8-150400.9.23.1 * python311-base-3.11.8-150400.9.23.1 * python311-core-debugsource-3.11.8-150400.9.23.1 * python311-dbm-3.11.8-150400.9.23.1 * python311-idle-3.11.8-150400.9.23.1 * python311-devel-3.11.8-150400.9.23.1 * python311-curses-debuginfo-3.11.8-150400.9.23.1 * python311-tk-3.11.8-150400.9.23.1 * python311-tk-debuginfo-3.11.8-150400.9.23.1 * python311-curses-3.11.8-150400.9.23.1 * python311-3.11.8-150400.9.23.1 * libpython3_11-1_0-debuginfo-3.11.8-150400.9.23.1 * libpython3_11-1_0-3.11.8-150400.9.23.1 ## References: * https://www.suse.com/security/cve/CVE-2022-25236.html * https://www.suse.com/security/cve/CVE-2023-27043.html * https://www.suse.com/security/cve/CVE-2023-6597.html * https://bugzilla.suse.com/show_bug.cgi?id=1196025 * https://bugzilla.suse.com/show_bug.cgi?id=1210638 * https://bugzilla.suse.com/show_bug.cgi?id=1219666 . Important security update for python311 tackling critical vulnerabilities. Apply patches tosafeguard your system now.. python311 Security Update, openSUSE Patch, Security Advisory, Expat Issue, Python Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 06, 2024 Important SuSE
100

openSUSE Leap 15.x: 2024:0033-1 Moderate: HTTP Header Injection Fix

* bsc#1217684 Cross-References: * CVE-2023-49081 . # Security update for python-aiohttp Announcement ID: SUSE-SU-2024:0033-1 Rating: moderate References: * bsc#1217684 Cross-References: * CVE-2023-49081 CVSS scores: * CVE-2023-49081 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-49081 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Python 3 Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-aiohttp fixes the following issues: * CVE-2023-49081: fixed an HTTP header injection via a crafted version (bsc#1217684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-33=1 * Python 3 Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2024-33=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-33=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.8.5-150400.10.8.1 * python311-aiohttp-debuginfo-3.8.5-150400.10.8.1 * python-aiohttp-debugsource-3.8.5-150400.10.8.1 * Python 3 Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.8.5-150400.10.8.1 * python311-aiohttp-debuginfo-3.8.5-150400.10.8.1 * python-aiohttp-debugsource-3.8.5-150400.10.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python311-aiohttp-3.8.5-150400.10.8.1 * python311-aiohttp-debuginfo-3.8.5-150400.10.8.1 * python-aiohttp-debugsource-3.8.5-150400.10.8.1 ## References: *https://www.suse.com/security/cve/CVE-2023-49081.html * https://bugzilla.suse.com/show_bug.cgi?id=1217684 . SUSE unveils a security update for python-aiohttp targeting a vulnerability in HTTP header injection classified as medium severity. openSUSE Security Update, Python Aiohttp Patch, HTTP Injection Fix. . LinuxSecurity.com Team

Calendar%202 Jan 05, 2024 SuSE
100

openSUSE: 2023:4988-1 low: python-pip arbitrary config injection

* bsc#1217353 Cross-References: * CVE-2023-5752 . # Security update for python-pip Announcement ID: SUSE-SU-2023:4988-1 Rating: low References: * bsc#1217353 Cross-References: * CVE-2023-5752 CVSS scores: * CVE-2023-5752 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2023-5752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Python 3 Module 15-SP4 * Python 3 Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-pip fixes the following issues: * CVE-2023-5752: Fixed injection of arbitrary configuration through Mercurial parameter (bsc#1217353). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4988=1 openSUSE-SLE-15.4-2023-4988=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4988=1 * Python 3 Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Python3-15-SP4-2023-4988=1 * Python 3 Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2023-4988=1 ## Package List: * openSUSE Leap 15.4 (noarch) * python311-pip-22.3.1-150400.17.12.1 * openSUSE Leap 15.5 (noarch) * python311-pip-22.3.1-150400.17.12.1 * Python 3 Module 15-SP4 (noarch) *python311-pip-22.3.1-150400.17.12.1 * Python 3 Module 15-SP5 (noarch) * python311-pip-22.3.1-150400.17.12.1 ## References: * https://www.suse.com/security/cve/CVE-2023-5752.html * https://bugzilla.suse.com/show_bug.cgi?id=1217353 . The recent python-pip update for CentOS resolves CVE-2023-5784, marked as low risk. Users are advised to upgrade as soon as possible.. python-pip update,SUSE security advisory,security patch,openSUSE updates. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Dec 28, 2023 Low SuSE
202

openSUSE 15.4 & 15.5: 2023:4288-1 Important: Python-Werkzeug DoS Fix

This update for python-Werkzeug fixes the following issues: CVE-2023-46136: Fixed a potential denial of service via large multipart file uploads (bsc#1216581).. # Security update for python-Werkzeug Announcement ID: SUSE-SU-2023:4288-1 Rating: important References: * bsc#1216581 Cross-References: * CVE-2023-46136 CVSS scores: * CVE-2023-46136 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-46136 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Python 3 Module 15-SP4 * Python 3 Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-Werkzeug fixes the following issues: * CVE-2023-46136: Fixed a potential denial of service via large multipart file uploads (bsc#1216581). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4288=1 openSUSE-SLE-15.4-2023-4288=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4288=1 * Python 3 Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Python3-15-SP4-2023-4288=1 * Python 3 Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2023-4288=1 ## Package List: * openSUSE Leap 15.4 (noarch) *python311-Werkzeug-2.3.6-150400.6.6.1 * openSUSE Leap 15.5 (noarch) * python311-Werkzeug-2.3.6-150400.6.6.1 * Python 3 Module 15-SP4 (noarch) * python311-Werkzeug-2.3.6-150400.6.6.1 * Python 3 Module 15-SP5 (noarch) * python311-Werkzeug-2.3.6-150400.6.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46136.html * https://bugzilla.suse.com/show_bug.cgi?id=1216581 . Important patch for python-Werkzeug tackles denial of service vulnerability, improving safety measures for openSUSE platforms.. python Werkzeug Security Advisory, openSUSE Security Update, denial of service fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 31, 2023 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200