* bsc#1210638 Cross-References: * CVE-2023-27043 . # Security update for python3 Announcement ID: SUSE-SU-2024:0581-1 Rating: moderate References: * bsc#1210638 Cross-References: * CVE-2023-27043 CVSS scores: * CVE-2023-27043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-27043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP5 * Development Tools Module 15-SP5 * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2023-27043: Fixed incorrectly parses e-mail addresses which contain a special character (bsc#1210638). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-581=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-581=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-581=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2024-581=1 * openSUSE Leap 15.3 zypper in -t patchSUSE-2024-581=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2024-581=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2024-581=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-581=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-581=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2024-581=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-581=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2024-581=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-581=1 ## Package List: * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-devel-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-devel-debuginfo-3.6.15-150300.10.54.1 * python3-tk-debuginfo-3.6.15-150300.10.54.1 * python3-curses-debuginfo-3.6.15-150300.10.54.1 * python3-dbm-3.6.15-150300.10.54.1 * python3-dbm-debuginfo-3.6.15-150300.10.54.1 * python3-curses-3.6.15-150300.10.54.1 * python3-tk-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-idle-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-tools-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 *python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python3-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-dbm-3.6.15-150300.10.54.1 * python3-testsuite-debuginfo-3.6.15-150300.10.54.1 * python3-doc-devhelp-3.6.15-150300.10.54.1 * python3-idle-3.6.15-150300.10.54.1 * python3-doc-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-devel-3.6.15-150300.10.54.1 * python3-curses-debuginfo-3.6.15-150300.10.54.1 * python3-dbm-debuginfo-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-devel-debuginfo-3.6.15-150300.10.54.1 * python3-tk-debuginfo-3.6.15-150300.10.54.1 * python3-tools-3.6.15-150300.10.54.1 * python3-tk-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * python3-testsuite-3.6.15-150300.10.54.1 * python3-curses-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.3 (x86_64) * libpython3_6m1_0-32bit-3.6.15-150300.10.54.1 * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.54.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libpython3_6m1_0-64bit-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-64bit-3.6.15-150300.10.54.1 * openSUSE Leap Micro 5.3 (aarch64 x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-dbm-3.6.15-150300.10.54.1 * python3-testsuite-debuginfo-3.6.15-150300.10.54.1 * python3-doc-devhelp-3.6.15-150300.10.54.1 * python3-idle-3.6.15-150300.10.54.1 * python3-doc-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-devel-3.6.15-150300.10.54.1 * python3-curses-debuginfo-3.6.15-150300.10.54.1 * python3-dbm-debuginfo-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-devel-debuginfo-3.6.15-150300.10.54.1 * python3-tk-debuginfo-3.6.15-150300.10.54.1 * python3-tools-3.6.15-150300.10.54.1 * python3-tk-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * python3-testsuite-3.6.15-150300.10.54.1 * python3-curses-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * openSUSE Leap 15.5 (x86_64) * libpython3_6m1_0-32bit-3.6.15-150300.10.54.1 * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro forRancher 5.3 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 * python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * libpython3_6m1_0-debuginfo-3.6.15-150300.10.54.1 * python3-base-debuginfo-3.6.15-150300.10.54.1 * libpython3_6m1_0-3.6.15-150300.10.54.1 * python3-3.6.15-150300.10.54.1 * python3-debuginfo-3.6.15-150300.10.54.1 *python3-base-3.6.15-150300.10.54.1 * python3-debugsource-3.6.15-150300.10.54.1 * python3-core-debugsource-3.6.15-150300.10.54.1 ## References: * https://www.suse.com/security/cve/CVE-2023-27043.html * https://bugzilla.suse.com/show_bug.cgi?id=1210638 . Python3 has introduced critical updates for email parsing vulnerabilities. Follow these steps for installation on various SUSE distributions:. SUSE Linux Update, Python3 Security Fix, Email Parsing Update. . Severity: Important. LinuxSecurity.com Team
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle-micro/5.1/toolbox ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:493-1 Container Tags : suse/sle-micro/5.1/toolbox:11.1 , suse/sle-micro/5.1/toolbox:11.1-2.2.354 , suse/sle-micro/5.1/toolbox:latest Container Release : 2.2.354 Severity : moderate Type : security References : 1205244 1208443 CVE-2022-45061 ----------------------------------------------------------------- The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:549-1 Released: Mon Feb 27 17:35:07 2023 Summary: Security update for python3 Type: security Severity: moderate References: 1205244,1208443,CVE-2022-45061 This update for python3 fixes the following issues: - CVE-2022-45061: Fixed DoS when IDNA decodes extremely long domain names (bsc#1205244). Bugfixes: - Fixed issue where email.generator.py replaces a non-existent header (bsc#1208443). The following package changes have been done: - libpython3_6m1_0-3.6.15-150300.10.40.1 updated - python3-base-3.6.15-150300.10.40.1 updated . SUSE: 2023:494-1 Security Update issued for System Package, rated with moderate criticality. SUSE Toolbox Update, Python3 Security Fix, SUSE Container Advisory. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3596-1 Rating: important References: #1176262 Cross-References: CVE-2019-20916 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Module for Web Scripting 12 SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python3 fixes the following issues: - Fixed a directory traversal in _download_http_url() (bsc#1176262 CVE-2019-20916) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2020-3596=1 - SUSE OpenStack Cloud Crowbar 8: zypperin -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-3596=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2020-3596=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-3596=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-3596=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2020-3596=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2020-3596=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-3596=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-3596=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2020-3596=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2020-3596=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-3596=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2020-3596=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-3596=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2020-3596=1 - SUSE Linux Enterprise Module for Web Scripting 12: zypper in -t patch SUSE-SLE-Module-Web-Scripting-12-2020-3596=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-3596=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2020-3596=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE OpenStack Cloud 9 (x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE OpenStack Cloud 8 (x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE OpenStack Cloud 7 (s390x x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-dbm-3.4.10-25.58.1 python3-dbm-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (ppc64le s390x x86_64): python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-tk-3.4.10-25.58.1 python3-tk-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP5 (ppc64le s390x x86_64): python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libpython3_4m1_0-32bit-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-32bit-3.4.10-25.58.1 python3-base-debuginfo-32bit-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (ppc64le s390x x86_64): python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le s390x x86_64): python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 - SUSE Linux EnterpriseModule for Web Scripting 12 (aarch64 ppc64le s390x x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 - SUSE Enterprise Storage 5 (x86_64): python3-devel-debuginfo-3.4.10-25.58.1 - HPE Helion Openstack 8 (x86_64): libpython3_4m1_0-3.4.10-25.58.1 libpython3_4m1_0-debuginfo-3.4.10-25.58.1 python3-3.4.10-25.58.1 python3-base-3.4.10-25.58.1 python3-base-debuginfo-3.4.10-25.58.1 python3-base-debugsource-3.4.10-25.58.1 python3-curses-3.4.10-25.58.1 python3-curses-debuginfo-3.4.10-25.58.1 python3-debuginfo-3.4.10-25.58.1 python3-debugsource-3.4.10-25.58.1 python3-devel-3.4.10-25.58.1 python3-devel-debuginfo-3.4.10-25.58.1 References: https://www.suse.com/security/cve/CVE-2019-20916.html https://bugzilla.suse.com/1176262 . A new version of python3 is now released to address a directory traversal vulnerability impacting multiple SUSE distributions.. SUSE Security Update, Python3 Patch, Directory Traversal, OpenStack Security, SUSE Linux Advisory. . Severity: Important. LinuxSecurity.com Team
Fix for CVE-2017-1000158. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2e5a17c4cc 2018-01-02 14:45:21.618934 --------------------------------------------------------------------------------Name : python33 Product : Fedora 27 Version : 3.3.7 Release : 2.fc27 URL : https://www.python.org/ Summary : Version 3.3 of the Python programming language Description : Python 3.3 package for developers. This package exists to allow developers to test their code against an older version of Python. This is not a full Python stack and if you wish to run your applications with Python 3.3, see other distributions that support it, such as CentOS or RHEL with Software Collections. --------------------------------------------------------------------------------Update Information: Fix for CVE-2017-1000158 --------------------------------------------------------------------------------References: [ 1 ] Bug #1519605 - CVE-2017-1000158 python33: python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1519605 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade python33' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.