Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
217

Oracle Linux 8 ELSA-2025-0746: Critical Update for GIMP and Python Packages

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0746 http://linux.oracle.com/errata/ELSA-2025-0746.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: gimp-2.8.22-26.module+el8.10.0+90497+ae78887f.x86_64.rpm gimp-devel-2.8.22-26.module+el8.10.0+90497+ae78887f.x86_64.rpm gimp-devel-tools-2.8.22-26.module+el8.10.0+90497+ae78887f.x86_64.rpm gimp-libs-2.8.22-26.module+el8.10.0+90497+ae78887f.x86_64.rpm pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.x86_64.rpm pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.x86_64.rpm pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpm python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.x86_64.rpm aarch64: gimp-2.8.22-26.module+el8.10.0+90497+ae78887f.aarch64.rpm gimp-devel-2.8.22-26.module+el8.10.0+90497+ae78887f.aarch64.rpm gimp-devel-tools-2.8.22-26.module+el8.10.0+90497+ae78887f.aarch64.rpm gimp-libs-2.8.22-26.module+el8.10.0+90497+ae78887f.aarch64.rpm pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm pygobject2-codegen-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm pygobject2-devel-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm pygobject2-doc-2.28.7-5.module+el8.10.0+90497+ae78887f.aarch64.rpm pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm pygtk2-codegen-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm pygtk2-devel-2.24.0-25.module+el8.9.0+90151+46a7e4b5.aarch64.rpm pygtk2-doc-2.24.0-25.module+el8.9.0+90151+46a7e4b5.noarch.rpm python2-cairo-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpm python2-cairo-devel-1.16.3-7.module+el8.10.0+90497+ae78887f.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//gimp-2.8.22-26.module+el8.10.0+90497+ae78887f.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pygobject2-2.28.7-5.module+el8.10.0+90497+ae78887f.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//pygtk2-2.24.0-25.module+el8.9.0+90151+46a7e4b5.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//python2-pycairo-1.16.3-7.module+el8.10.0+90497+ae78887f.src.rpm Related CVEs: CVE-2023-44442 CVE-2023-44443 CVE-2023-44444 Description of changes: gimp [2:2.28.22-26] - bump spec pygobject2 [2.28.7-5] - bump spec to fix NVR pygtk2 [2.24.0-25] - Fix shebang mangling for _prefix=app (#1907579) - disable numpy for flatpak (#1907579) python2-pycairo [1.16.3-7] - bump spec for NVR fix _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Crucial announcement regarding Oracle Linux 8 highlights essential security enhancements for GIMP and associated software to bolster system safety.. Oracle Linux Update, Important Security Fixes, GIMP Package Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 29, 2025 Critical Oracle
198

Arch Linux: 2021-03-27 High Severity: Python2 Code Issues and Fixes

The package python2 before version 2.7.18-3 is vulnerable to multiple issues including arbitrary code execution, url request injection and denial of service. . Arch Linux Security Advisory ASA-202103-27 ========================================= Severity: High Date : 2021-03-25 CVE-ID : CVE-2019-20907 CVE-2020-8492 CVE-2020-26116 CVE-2020-27619 CVE-2021-3177 CVE-2021-23336 Package : python2 Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1597 Summary ====== The package python2 before version 2.7.18-3 is vulnerable to multiple issues including arbitrary code execution, url request injection and denial of service. Resolution ========= Upgrade to 2.7.18-3. # pacman -Syu "python2> =2.7.18-3" The problems have been fixed upstream but no release is available yet. Workaround ========= None. Description ========== - CVE-2019-20907 (denial of service) In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation. - CVE-2020-8492 (denial of service) Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking. - CVE-2020-26116 (url request injection) http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. - CVE-2020-27619 (arbitrary code execution) In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP. - CVE-2021-3177 (arbitrary code execution) Python 3.x through 3.9.1 has a buffer overflow in PyCArg_reprin _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely. - CVE-2021-23336 (url request injection) The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter. The package python-django contains a copy of urllib.parse.parse_qsl() which was added to backport some security fixes. A further security fix has been issued in versions 3.1.7, 3.0.13 and 2.2.19 such that parse_qsl() no longer allows using ; as a query parameter separator by default. Impact ===== A remote attacker could execute code or crash the application through crafted files or HTTP requests. Furthermore, a remote attacker could inject arbitrary headers or poison web caches through craftedHTTP requests. References ========= https://bugs.archlinux.org/task/68063 https://bugs.python.org/issue39017 https://github.com/python/cpython/pull/21454 https://github.com/python/cpython/commit/5a8d121a1f3ef5ad7c105ee378cc79a3eac0c7d4 https://bugs.python.org/issue39503 https://github.com/python/cpython/pull/18284 https://github.com/python/cpython/commit/0b297d4ff1c0e4480ad33acae793fbaf4bf015b4 https://python-security.readthedocs.io/vuln/http-header-injection-method.html https://bugs.python.org/issue39603 https://github.com/python/cpython/pull/18485 https://github.com/python/cpython/commit/8ca8a2e8fb068863c1138f07e3098478ef8be12e https://python-security.readthedocs.io/vuln/cjk-codec-download-eval.html https://bugs.python.org/issue41944 https://github.com/python/cpython/pull/22575 https://github.com/python/cpython/commit/b664a1df4ee71d3760ab937653b10997081b1794 https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html https://bugs.python.org/issue42938 https://github.com/python/cpython/pull/24239 https://github.com/python/cpython/commit/c347cbe694743cee120457aa6626712f7799a932 https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/ https://bugs.python.org/issue42967 https://github.com/python/cpython/pull/24297 https://github.com/python/cpython/commit/c9f07813ab8e664d8c34413c4fc2d4f86c061a92 https://www.djangoproject.com/weblog/2021/feb/19/security-releases/ https://github.com/django/django/commit/8f6d431b08cbb418d9144b976e7b972546607851 https://security.archlinux.org/CVE-2019-20907 https://security.archlinux.org/CVE-2020-8492 https://security.archlinux.org/CVE-2020-26116 https://security.archlinux.org/CVE-2020-27619 https://security.archlinux.org/CVE-2021-3177 https://security.archlinux.org/CVE-2021-23336 . A number of critical vulnerabilities identified in Arch Linux's python3 package necessitate immediate updates to address potential risks.. Arch Linux Python2 Security, Code Execution Risks, Update Recommendations for Python2. . LinuxSecurity.com Team

Calendar 2 Mar 26, 2021 ArchLinux
89

Fedora 31: 2020-e33acdea18 Critical: Python2 Control Char Fix

Fix CVE-2020-26116: Reject control chars in HTTP method in httplib. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-e33acdea18 2020-10-30 01:14:56.947527 --------------------------------------------------------------------------------Name : python2 Product : Fedora 31 Version : 2.7.18 Release : 6.fc31 URL : https://www.python.org/ Summary : An interpreted, interactive, object-oriented programming language Description : Python 2 is an old version of the language that is incompatible with the 3.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed in the 3.x line. Note that documentation for Python 2 is provided in the python2-docs package. This package provides the "python2" executable; most of the actual implementation is within the "python2-libs" package. --------------------------------------------------------------------------------Update Information: Fix CVE-2020-26116: Reject control chars in HTTP method in httplib --------------------------------------------------------------------------------ChangeLog: * Wed Sep 30 2020 Petr Viktorin - 2.7.18-6 - CVE-2020-26116: Reject control chars in HTTP method in httplib.putrequest * Tue Sep 29 2020 Petr Viktorin - 2.7.18-5 - Import patches from GitHub tree --------------------------------------------------------------------------------References: [ 1 ] Bug #1883248 - CVE-2020-26116 python2: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1883248 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-e33acdea18' at the command line. Formore information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . This report addresses CVE-2021-34322 impacting python3, providing insights on resolving issues with invalid inputs in URL parsing.. Fedora Update, Python2 Security Fix, HTTP Method Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 29, 2020 Critical Fedora
89

Fedora 31: 2020-826b24c329 moderate: Python2 Tar Handling Update

Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-826b24c329 2020-08-06 03:56:53.814289 --------------------------------------------------------------------------------Name : python2 Product : Fedora 31 Version : 2.7.18 Release : 2.fc31 URL : https://www.python.org/ Summary : An interpreted, interactive, object-oriented programming language Description : Python 2 is an old version of the language that is incompatible with the 3.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed in the 3.x line. Note that documentation for Python 2 is provided in the python2-docs package. This package provides the "python2" executable; most of the actual implementation is within the "python2-libs" package. --------------------------------------------------------------------------------Update Information: Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907) --------------------------------------------------------------------------------ChangeLog: * Mon Jul 20 2020 Petr Viktorin - 2.7.18-2 - Avoid infinite loop when reading specially crafted TAR files (CVE-2019-20907) Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1856481 --------------------------------------------------------------------------------References: [ 1 ] Bug #1856485 - CVE-2019-20907 python2: python: infinite loop in the tarfile module via crafted TAR archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1856485 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-826b24c329' at thecommand line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora enhances Python 2 to address endless loop problems in TAR file management, guaranteeing more secure file operations and system reliability.. Python 2 Update,Fedora Update Notification,TAR File Security Fix,File Handling Error. . LinuxSecurity.com Team

Calendar 2 Aug 05, 2020 Fedora
198

Arch Linux 201911-4 Severe: Python2 Security Information Leak Issue

The package python2 before version 2.7.17-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-201911-4 ======================================== Severity: High Date : 2019-11-03 CVE-ID : CVE-2019-9636 Package : python2 Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-978 Summary ====== The package python2 before version 2.7.17-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 2.7.17-1. # pacman -Syu "python2> =2.7.17-1" The problem has been fixed upstream in version 2.7.17. Workaround ========= None. Description ========== Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. A specially crafted URL could be incorrectly parsed by urllib.parse.urlsplit and urllib.parse.urlparse to locate cookies or authentication data and send that information to a different host than when parsed correctly. Impact ===== A remote attacker is able to craft a malicious URL and transfer private data to a different host than expected. References ========= https://python-security.readthedocs.io/vuln/urlsplit-nfkc-normalization.html https://github.com/python/cpython/commit/daad2c482c91de32d8305abbccc76a5de8b3a8be https://github.com/python/cpython/commit/f61599b050c621386a3fc6bc480359e2d3bb93de https://security.archlinux.org/CVE-2019-9636 . Arch Linux Security Alert ASA-202305-8 highlights a critical information leakage vulnerability in python3 prior to version 3.8.10-2; users should update promptly.. python2 information disclosure Arch Linux security advisory remote exploit. . LinuxSecurity.com Team

Calendar 2 Nov 04, 2019 ArchLinux
89

Fedora 30: FEDORA-2019-0c91ce7b3c Critical: Python 2 Segfault Issues

Update legacy Python to 2.7.16. Most significant improvement is that is builds against OpenSSL 1.1.1. See [upstream release announcement](https://www.python.org/downloads/release/python-2716/) and [changelog](.rst) (+ [rc1 changelog](. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-0c91ce7b3c 2019-03-29 19:07:28.727610 --------------------------------------------------------------------------------Name : python2-docs Product : Fedora 30 Version : 2.7.16 Release : 1.fc30 URL : https://www.python.org/ Summary : Documentation for the Python 2 programming language Description : The python2-docs package contains documentation on the Python 2 programming language and interpreter. Install the python2-docs package if you'd like to use the documentation for the Python 2 language. --------------------------------------------------------------------------------Update Information: Update legacy Python to 2.7.16. Most significant improvement is that is builds against OpenSSL 1.1.1. See [upstream release announcement](https://www.python.org/downloads/release/python-2716/) and [changelog](https://github.com/python/cpython/blob/2.7/Misc/NEWS.d/2.7.16.rst) (+ [rc1 changelog](rc1.rst)). Fixes the following CVEs: * [CVE-2019-5010](https://access.redhat.com/security/cve/cve-2019-5010) Fix a NULL pointer deref in ssl module. The cert parser did not handle CRL distribution points with empty DP or URI correctly. A malicious or buggy certificate can result into segfault. Vulnerability (TALOS-2018-0758) reported by Colin Read and Nicolas Edet of Cisco. * [CVE-2013-1752](https://access.redhat.com/security/cve/cve-2013-1752): Change use of readline() in `imaplib.IMAP4_SSL` to limit line length. ([CVE-2018-14647](https://access.redhat.com/security/cve/cve-2018-14647) is listed in upstream changelog, but it was already backported in Fedora.) Note that Python 2 is deprecated in Fedora 30 and usersare advised to switch to Python 3. Upstream support of Python 2 ends on 2020-01-01. --------------------------------------------------------------------------------References: [ 1 ] Bug #1643450 - Python 2 is built against an old OpenSSL (1.0.1) while 1.1.1 is available in F29 https://bugzilla.redhat.com/show_bug.cgi?id=1643450 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-0c91ce7b3c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora's Python 2.7.16 receives a security patch aimed at enhancing OpenSSL 1.1.1, addressing major vulnerabilities and overall stability.. python2, fedora, openssl, documentation, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 29, 2019 Critical Fedora
89

Fedora 30: FEDORA-2019-0c91ce7b3c Critical: Python2 OpenSSL Fix

Update legacy Python to 2.7.16. Most significant improvement is that is builds against OpenSSL 1.1.1. See [upstream release announcement](https://www.python.org/downloads/release/python-2716/) and [changelog](.rst) (+ [rc1 changelog](. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-0c91ce7b3c 2019-03-29 19:07:28.727610 --------------------------------------------------------------------------------Name : python2 Product : Fedora 30 Version : 2.7.16 Release : 1.fc30 URL : https://www.python.org/ Summary : An interpreted, interactive, object-oriented programming language Description : Python 2 is an old version of the language that is incompatible with the 3.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed in the 3.x line. Note that documentation for Python 2 is provided in the python2-docs package. This package provides the "python2" executable; most of the actual implementation is within the "python2-libs" package. --------------------------------------------------------------------------------Update Information: Update legacy Python to 2.7.16. Most significant improvement is that is builds against OpenSSL 1.1.1. See [upstream release announcement](https://www.python.org/downloads/release/python-2716/) and [changelog](https://github.com/python/cpython/blob/2.7/Misc/NEWS.d/2.7.16.rst) (+ [rc1 changelog](rc1.rst)). Fixes the following CVEs: * [CVE-2019-5010](https://access.redhat.com/security/cve/cve-2019-5010) Fix a NULL pointer deref in ssl module. The cert parser did not handle CRL distribution points with empty DP or URI correctly. A malicious or buggy certificate can result into segfault. Vulnerability (TALOS-2018-0758) reported by Colin Read and Nicolas Edet of Cisco. * [CVE-2013-1752](https://access.redhat.com/security/cve/cve-2013-1752): Change use of readline() in `imaplib.IMAP4_SSL` to limit line length. ([CVE-2018-14647](https://access.redhat.com/security/cve/cve-2018-14647) is listed in upstream changelog, but it was already backported in Fedora.) Note that Python 2 is deprecated in Fedora 30 and users are advised to switch to Python 3. Upstream support of Python 2 ends on 2020-01-01. --------------------------------------------------------------------------------References: [ 1 ] Bug #1643450 - Python 2 is built against an old OpenSSL (1.0.1) while 1.1.1 is available in F29 https://bugzilla.redhat.com/show_bug.cgi?id=1643450 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-0c91ce7b3c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The upgrade to the legacy Python version 2.7.16 emphasizes essential enhancements, especially regarding OpenSSL compatibility.. Python2 Update, Fedora Security, OpenSSL Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 29, 2019 Critical Fedora
89

Fedora 28 Python2-Django1.11 Security Patch: CVE-2019-3498 & CVE-2019-6975

- CVE-2019-3498: Content spoofing possibility in the default 404 page - CVE-2019-6975: Memory exhaustion in django.utils.numberformat.format() - Fixed a race condition in QuerySet.update_or_create() that could result in data loss - geo: Prevented repetitive calls to geos_version_tuple() in the WKBWriter class. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-5ad2149e99 2019-03-20 21:17:00.935171 --------------------------------------------------------------------------------Name : python2-django1.11 Product : Fedora 28 Version : 1.11.20 Release : 1.fc28 URL : http://www.djangoproject.com/ Summary : Version 1.11 LTS of Django, a high-level Python Web framework Description : This package provides Django in version 1.11 LTS, the last release to support Python 2. Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. --------------------------------------------------------------------------------Update Information: - CVE-2019-3498: Content spoofing possibility in the default 404 page -CVE-2019-6975: Memory exhaustion in django.utils.numberformat.format() - Fixed a race condition in QuerySet.update_or_create() that could result in data loss -geo: Prevented repetitive calls to geos_version_tuple() in the WKBWriter class --------------------------------------------------------------------------------ChangeLog: * Mon Feb 18 2019 Petr Viktorin - 1.11.20-1 - Update to the 1.11.20 security fix release - CVE-2019-6975: Memory exhaustion in django.utils.numberformat.format() * Sat Feb 2 2019 Fedora Release Engineering - 1.11.18-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Tue Jan 8 2019 Petr Viktorin - 1.11.18-1 - Update to the 1.11.18 security fix release - CVE-2019-3498: Content spoofingpossibility in the default 404 page - geo: Prevented repetitive calls to geos_version_tuple() in the WKBWriter class - Officially supports Python 3.7 * Thu Nov 8 2018 Petr Viktorin - 1.11.16-2 - Switch locale from en_US.utf-8 to C.utf-8 for tests * Fri Aug 3 2018 Petr Viktorin - 1.11.16-1 - Update to 1.11.16 release -- data loss bug fix Fixed a race condition in QuerySet.update_or_create() that could result in data loss - Remove optional test dependencies - Exclude templates from shebang mangling * Fri Aug 3 2018 Petr Viktorin - 1.11.15-2 - Update to 1.11.15 security release (CVE-2018-14574) CVE-2018-14574: Open redirect possibility in CommonMiddleware https://docs.djangoproject.com/en/2.0/releases/1.11.15/ * Sat Jul 14 2018 Fedora Release Engineering - 1.11.14-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Mon Jun 4 2018 Petr Viktorin - 1.11.14-1 - update to 1.11.14, fixing a memory usage regression and a GIS bug https://docs.djangoproject.com/en/2.0/releases/1.11.14/ * Thu May 3 2018 Matthias Runge - 1.11.13-1 - update to 1.11.13, fixing regressions and a crash --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5ad2149e99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Crucial security patch for Fedora 28 impacting python2-django1.11, targeting content manipulation and memory vulnerabilities.. Fedora Security, Django Update, Python Security, Content Spoofing, Memory Exhaustion. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 20, 2019 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here