An update that solves one vulnerability can now be installed.. # Security update for python3 Announcement ID: SUSE-SU-2025:1056-1 Release Date: 2025-03-28T17:06:49Z Rating: low References: * bsc#1233307 Cross-References: * CVE-2024-11168 CVSS scores: * CVE-2024-11168 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X * CVE-2024-11168 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-11168 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X * CVE-2024-11168 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP6 * Development Tools Module 15-SP6 * openSUSE Leap 15.3 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2024-11168: Fixed improper validation of IPv6 and IPvFuture addresses (bsc#1233307). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-1056=1 * openSUSE Leap 15.6 zypper in -t patchopenSUSE-SLE-15.6-2025-1056=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-1056=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-1056=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-1056=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-1056=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-1056=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-1056=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-1056=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1056=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2025-1056=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python3-tk-debuginfo-3.6.15-150300.10.84.1 * python3-idle-3.6.15-150300.10.84.1 * python3-tk-3.6.15-150300.10.84.1 * python3-dbm-debuginfo-3.6.15-150300.10.84.1 * python3-curses-3.6.15-150300.10.84.1 * python3-devel-3.6.15-150300.10.84.1 * python3-tools-3.6.15-150300.10.84.1 * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-doc-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * python3-testsuite-debuginfo-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-curses-debuginfo-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-devel-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * python3-doc-devhelp-3.6.15-150300.10.84.1 * python3-dbm-3.6.15-150300.10.84.1 * python3-testsuite-3.6.15-150300.10.84.1 * openSUSELeap 15.3 (x86_64) * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.84.1 * libpython3_6m1_0-32bit-3.6.15-150300.10.84.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libpython3_6m1_0-64bit-debuginfo-3.6.15-150300.10.84.1 * libpython3_6m1_0-64bit-3.6.15-150300.10.84.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python3-tk-debuginfo-3.6.15-150300.10.84.1 * python3-idle-3.6.15-150300.10.84.1 * python3-tk-3.6.15-150300.10.84.1 * python3-dbm-debuginfo-3.6.15-150300.10.84.1 * python3-curses-3.6.15-150300.10.84.1 * python3-devel-3.6.15-150300.10.84.1 * python3-tools-3.6.15-150300.10.84.1 * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-doc-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * python3-testsuite-debuginfo-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-curses-debuginfo-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-devel-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * python3-doc-devhelp-3.6.15-150300.10.84.1 * python3-dbm-3.6.15-150300.10.84.1 * python3-testsuite-3.6.15-150300.10.84.1 * openSUSE Leap 15.6 (x86_64) * libpython3_6m1_0-32bit-debuginfo-3.6.15-150300.10.84.1 * libpython3_6m1_0-32bit-3.6.15-150300.10.84.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-base-3.6.15-150300.10.84.1 *python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-tk-debuginfo-3.6.15-150300.10.84.1 * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-dbm-3.6.15-150300.10.84.1 * python3-idle-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 *libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-curses-debuginfo-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * python3-dbm-debuginfo-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-curses-3.6.15-150300.10.84.1 * python3-devel-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * python3-devel-3.6.15-150300.10.84.1 * python3-tk-3.6.15-150300.10.84.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-core-debugsource-3.6.15-150300.10.84.1 * python3-tools-3.6.15-150300.10.84.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * python3-base-3.6.15-150300.10.84.1 * python3-base-debuginfo-3.6.15-150300.10.84.1 * python3-debugsource-3.6.15-150300.10.84.1 * python3-core-debugsource-3.6.15-150300.10.84.1 * libpython3_6m1_0-3.6.15-150300.10.84.1 * python3-3.6.15-150300.10.84.1 * libpython3_6m1_0-debuginfo-3.6.15-150300.10.84.1 * python3-debuginfo-3.6.15-150300.10.84.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11168.html * https://bugzilla.suse.com/show_bug.cgi?id=1233307 . Update for python3 addresses CVE-2024-11168 to improve security on openSUSE systems.. update, solves, vulnerability, installed, security, python3, announce. . Severity: Low. LinuxSecurity.com Team
* bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168 . # Security update for python3 Announcement ID: SUSE-SU-2024:4166-1 Release Date: 2024-12-04T10:31:32Z Rating: low References: * bsc#1231795 * bsc#1233307 Cross-References: * CVE-2024-11168 CVSS scores: * CVE-2024-11168 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X * CVE-2024-11168 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-11168 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python3 fixes the following issues: * CVE-2024-11168: Fixed improper validation of IPv6 and IPvFuture addresses (bsc#1233307) Other fixes: \- Remove -IVendor/ from python-config (bsc#1231795) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2024-4166=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python3-base-debuginfo-3.4.10-25.145.1 * libpython3_4m1_0-debuginfo-3.4.10-25.145.1 * python3-base-debugsource-3.4.10-25.145.1 * python3-devel-debuginfo-3.4.10-25.145.1 * libpython3_4m1_0-3.4.10-25.145.1 * libpython3_4m1_0-32bit-3.4.10-25.145.1 *python3-3.4.10-25.145.1 * python3-tk-debuginfo-3.4.10-25.145.1 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.145.1 * python3-debugsource-3.4.10-25.145.1 * python3-curses-debuginfo-3.4.10-25.145.1 * python3-debuginfo-3.4.10-25.145.1 * python3-devel-3.4.10-25.145.1 * python3-base-debuginfo-32bit-3.4.10-25.145.1 * python3-base-3.4.10-25.145.1 * python3-curses-3.4.10-25.145.1 * python3-tk-3.4.10-25.145.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11168.html * https://bugzilla.suse.com/show_bug.cgi?id=1231795 * https://bugzilla.suse.com/show_bug.cgi?id=1233307 . SUSE has rolled out a Python3 update, classified as low severity, addressing IPv6 validation problems along with installation guidelines.. python3 update, SUSE security, security patch, SUSE Linux Enterprise, SLE advisory. . Severity: Low. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-4243 http://linux.oracle.com/errata/ELSA-2024-4243.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: python3.12-3.12.3-2.el8_10.x86_64.rpm python3.12-devel-3.12.3-2.el8_10.i686.rpm python3.12-devel-3.12.3-2.el8_10.x86_64.rpm python3.12-libs-3.12.3-2.el8_10.i686.rpm python3.12-libs-3.12.3-2.el8_10.x86_64.rpm python3.12-rpm-macros-3.12.3-2.el8_10.noarch.rpm python3.12-tkinter-3.12.3-2.el8_10.x86_64.rpm python3.12-3.12.3-2.el8_10.i686.rpm python3.12-debug-3.12.3-2.el8_10.i686.rpm python3.12-debug-3.12.3-2.el8_10.x86_64.rpm python3.12-idle-3.12.3-2.el8_10.i686.rpm python3.12-idle-3.12.3-2.el8_10.x86_64.rpm python3.12-test-3.12.3-2.el8_10.i686.rpm python3.12-test-3.12.3-2.el8_10.x86_64.rpm python3.12-tkinter-3.12.3-2.el8_10.i686.rpm aarch64: python3.12-3.12.3-2.el8_10.aarch64.rpm python3.12-devel-3.12.3-2.el8_10.aarch64.rpm python3.12-libs-3.12.3-2.el8_10.aarch64.rpm python3.12-rpm-macros-3.12.3-2.el8_10.noarch.rpm python3.12-tkinter-3.12.3-2.el8_10.aarch64.rpm python3.12-debug-3.12.3-2.el8_10.aarch64.rpm python3.12-idle-3.12.3-2.el8_10.aarch64.rpm python3.12-test-3.12.3-2.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//python3.12-3.12.3-2.el8_10.src.rpm Related CVEs: CVE-2024-0450 Description of changes: [3.12.3-2] - Enable importing of hash-based .pyc files under FIPS mode Resolves: RHEL-40776 [3.12.3-1] - Update to 3.12.3 Related: RHEL-33685 [3.12.2-3] - Move all test modules to the python3-test package, namely: - __phello__ - _xxsubinterpreters - xxlimited - xxlimited_35 - xxsubtype [3.12.2-2] - Fix tests for XMLPullParser with Expat with fixed CVE [3.12.2-1] - Update to 3.12.2 Resolves: RHEL-33685 _______________________________________________ El-errata mailing list
Important: python3.11 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:4077", "synopsis": "Important: python3.11 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for python3.11.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.\n\nSecurity Fix(es):\n\n* python: Path traversal on tempfile.TemporaryDirectory (CVE-2023-6597)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2276518", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2276518", "description": ""}], "cves": [{"name": "CVE-2023-6597", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-6597", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-07-02T14:11:30.465192Z", "rpms": {"Rocky Linux 9": {"nvras": ["python3.11-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-0:3.11.7-1.el9_4.1.i686.rpm", "python3.11-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-0:3.11.7-1.el9_4.1.src.rpm", "python3.11-0:3.11.7-1.el9_4.1.x86_64.rpm", "python3.11-debug-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-debug-0:3.11.7-1.el9_4.1.i686.rpm", "python3.11-debug-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-debug-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-debug-0:3.11.7-1.el9_4.1.x86_64.rpm","python3.11-debuginfo-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-debuginfo-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-debuginfo-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-debuginfo-0:3.11.7-1.el9_4.1.x86_64.rpm", "python3.11-debugsource-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-debugsource-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-debugsource-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-debugsource-0:3.11.7-1.el9_4.1.x86_64.rpm", "python3.11-devel-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-devel-0:3.11.7-1.el9_4.1.i686.rpm", "python3.11-devel-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-devel-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-devel-0:3.11.7-1.el9_4.1.x86_64.rpm", "python3.11-idle-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-idle-0:3.11.7-1.el9_4.1.i686.rpm", "python3.11-idle-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-idle-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-idle-0:3.11.7-1.el9_4.1.x86_64.rpm", "python3.11-libs-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-libs-0:3.11.7-1.el9_4.1.i686.rpm", "python3.11-libs-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-libs-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-libs-0:3.11.7-1.el9_4.1.x86_64.rpm", "python3.11-test-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-test-0:3.11.7-1.el9_4.1.i686.rpm", "python3.11-test-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-test-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-test-0:3.11.7-1.el9_4.1.x86_64.rpm", "python3.11-tkinter-0:3.11.7-1.el9_4.1.aarch64.rpm", "python3.11-tkinter-0:3.11.7-1.el9_4.1.i686.rpm", "python3.11-tkinter-0:3.11.7-1.el9_4.1.ppc64le.rpm", "python3.11-tkinter-0:3.11.7-1.el9_4.1.s390x.rpm", "python3.11-tkinter-0:3.11.7-1.el9_4.1.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Uncover the significant python3.11 security patch for Rocky Linux 9 designed to mitigate severe vulnerabilities.. Rocky Linux Security, Python3 Update, Critical Patch, System Protection. . Severity: Important. LinuxSecurity.com Team
The container suse/389-ds was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/389-ds ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3178-1 Container Tags : suse/389-ds:2.2 , suse/389-ds:2.2-15.4 , suse/389-ds:latest Container Release : 15.4 Severity : important Type : security References : 1211829 1212819 1212910 1214692 1215026 CVE-2023-38039 CVE-2023-40217 ----------------------------------------------------------------- The container suse/389-ds was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:3814-1 Released: Wed Sep 27 18:08:17 2023 Summary: Recommended update for glibc Type: recommended Severity: moderate References: 1211829,1212819,1212910 This update for glibc fixes the following issues: - nscd: Fix netlink cache invalidation if epoll is used (bsc#1212910, BZ #29415) - Restore lookup of IPv4 mapped addresses in files database (bsc#1212819, BZ #25457) - elf: Remove excessive p_align check on PT_LOAD segments (bsc#1211829, BZ #28688) - elf: Properly align PT_LOAD segments (bsc#1211829, BZ #28676) - ld.so: Always use MAP_COPY to map the first segment (BZ #30452) - add GB18030-2022 charmap (jsc#PED-4908, BZ #30243) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3823-1 Released: Wed Sep 27 18:42:38 2023 Summary: Security update for curl Type: security Severity: important References: 1215026,CVE-2023-38039 This update for curl fixes the following issues: - CVE-2023-38039: Fixed possible DoS when receiving too large HTTP header. (bsc#1215026) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:3828-1 Released: Wed Sep 27 19:07:38 2023 Summary: Security update for python3 Type: security Severity: important References: 1214692,CVE-2023-40217 This update for python3 fixes the following issues: - CVE-2023-40217: Fixed TLS handshake bypass on closed sockets (bsc#1214692). The following package changes have been done: - glibc-2.31-150300.58.1 updated - libcurl4-8.0.1-150400.5.29.1 updated - python3-base-3.6.15-150300.10.51.1 updated - libpython3_6m1_0-3.6.15-150300.10.51.1 updated - python3-3.6.15-150300.10.51.1 updated - container:sles15-image-15.0.0-36.5.37 updated . Crucial security patches for SUSE container suse/389-ds addressing various vulnerabilities and improving overall robustness.. SUSE Security Update, Container Security Advisory, SUSE-389-DS Update, Curl Fix, Python3 Update. . Severity: Important. LinuxSecurity.com Team
An update for python3 is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: python3 security update Advisory ID: RHSA-2023:3936-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:3936 Issue date: 2023-06-29 CVE Names: CVE-2023-24329 ==================================================================== 1. Summary: An update for python3 is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS E4S (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: urllib.parse url blocklisting bypass (CVE-2023-24329) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2173917 - CVE-2023-24329 python: urllib.parse url blocklisting bypass 6. Package List: Red Hat Enterprise Linux AppStream E4S (v. 8.1): aarch64: platform-python-debug-3.6.8-15.1.el8_1.1.aarch64.rpm platform-python-devel-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.aarch64.rpm python3-idle-3.6.8-15.1.el8_1.1.aarch64.rpm python3-tkinter-3.6.8-15.1.el8_1.1.aarch64.rpm ppc64le: platform-python-debug-3.6.8-15.1.el8_1.1.ppc64le.rpm platform-python-devel-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debugsource-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-idle-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-tkinter-3.6.8-15.1.el8_1.1.ppc64le.rpm s390x: platform-python-debug-3.6.8-15.1.el8_1.1.s390x.rpm platform-python-devel-3.6.8-15.1.el8_1.1.s390x.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.s390x.rpm python3-debugsource-3.6.8-15.1.el8_1.1.s390x.rpm python3-idle-3.6.8-15.1.el8_1.1.s390x.rpm python3-tkinter-3.6.8-15.1.el8_1.1.s390x.rpm x86_64: platform-python-3.6.8-15.1.el8_1.1.i686.rpm platform-python-debug-3.6.8-15.1.el8_1.1.i686.rpm platform-python-debug-3.6.8-15.1.el8_1.1.x86_64.rpm platform-python-devel-3.6.8-15.1.el8_1.1.i686.rpm platform-python-devel-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.i686.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.i686.rpm python3-debugsource-3.6.8-15.1.el8_1.1.x86_64.rpm python3-idle-3.6.8-15.1.el8_1.1.i686.rpm python3-idle-3.6.8-15.1.el8_1.1.x86_64.rpm python3-test-3.6.8-15.1.el8_1.1.i686.rpm python3-tkinter-3.6.8-15.1.el8_1.1.i686.rpm python3-tkinter-3.6.8-15.1.el8_1.1.x86_64.rpm Red Hat Enterprise Linux BaseOS E4S (v.8.1): Source: python3-3.6.8-15.1.el8_1.1.src.rpm aarch64: platform-python-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.aarch64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.aarch64.rpm python3-libs-3.6.8-15.1.el8_1.1.aarch64.rpm python3-test-3.6.8-15.1.el8_1.1.aarch64.rpm ppc64le: platform-python-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-debugsource-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-libs-3.6.8-15.1.el8_1.1.ppc64le.rpm python3-test-3.6.8-15.1.el8_1.1.ppc64le.rpm s390x: platform-python-3.6.8-15.1.el8_1.1.s390x.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.s390x.rpm python3-debugsource-3.6.8-15.1.el8_1.1.s390x.rpm python3-libs-3.6.8-15.1.el8_1.1.s390x.rpm python3-test-3.6.8-15.1.el8_1.1.s390x.rpm x86_64: platform-python-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.i686.rpm python3-debuginfo-3.6.8-15.1.el8_1.1.x86_64.rpm python3-debugsource-3.6.8-15.1.el8_1.1.i686.rpm python3-debugsource-3.6.8-15.1.el8_1.1.x86_64.rpm python3-libs-3.6.8-15.1.el8_1.1.i686.rpm python3-libs-3.6.8-15.1.el8_1.1.x86_64.rpm python3-test-3.6.8-15.1.el8_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBZJ2or9zjgjWX9erEAQgEGQ/+NF29rUsWpqKyPuuOWMqF0KJRjfd3sv1w 6pp2p/7xR1rNrkJeMv2vU0Mv9n9xR7nVGnVEfkcxwDaUsrja0h/97yie8Z4FcXWI haTj5Oe83lKLxy4XomSiBIXRgp8svHCH5cPxe6p9Ezx9+xSg4QKW8Wz2T+Q7U13u ZeVaOeg/EIbJGa2+gQ1tUBb28xcnXavbGKbHNRUGLsgIPHF8tmXufTcPCM1GMPCr 07NMfSJuwFt9CjlZXZIsfn2C1ADL+aRVMejvV/CY5Cn4cc6IJqX9nM2DpkiUgZjf +zjUrTXH/LGR7NOcyUyyWErJQJg9SoaJxWdyoUm9Pbs7YkF8QzN7UU0+2VIkdT5e dujPuFr435gaacj05xCWRgxAvck1Y6aYXaC8YJNM+KUyzZYcQyfGQB0RK9xHPorC eZjiqfii7qDEBJaDglX6fOHVwrQGrQ9sHSMToEBurlc+E6Wjvpsh45NcuLYOZubg TmShSgcEoLCN/K6NkAuo9L4SpWgmAU/IZW23nNpurWGrAI3Ht8FxRAgAQuieR4ic CW7OsFxx4/T/ZXKp/uXghRJBZHeP8nvY/0ymh11/DwQQ1lGGhxEVEx4jUjV1dbJO Alul8f5VjR7+eXYQsPWHZnx0dowuW/2NtBzzNxX83LgREzaf5U2HHY7AUy0jGe4X 8U64p6Xx3FU=muR1 -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The container suse/389-ds was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/389-ds ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1946-1 Container Tags : suse/389-ds:2.0 , suse/389-ds:2.0-22.5 , suse/389-ds:latest Container Release : 22.5 Severity : moderate Type : security References : 1203750 1211158 CVE-2007-4559 ----------------------------------------------------------------- The container suse/389-ds was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2517-1 Released: Thu Jun 15 07:09:52 2023 Summary: Security update for python3 Type: security Severity: moderate References: 1203750,1211158,CVE-2007-4559 This update for python3 fixes the following issues: - CVE-2007-4559: Fixed filter for tarfile.extractall (bsc#1203750). - Fixed unittest.mock.patch.dict returns function when applied to coroutines (bsc#1211158). The following package changes have been done: - python3-base-3.6.15-150300.10.48.1 updated - libpython3_6m1_0-3.6.15-150300.10.48.1 updated . SUSE Container Notification regarding suse/389-ds enhancements featuring updates that address moderate vulnerability concerns, alongside adjustments for python3.. SUSE Container Update,suse/389-ds,python3 security,container security. . LinuxSecurity.com Team
The container bci/python was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/python ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:477-1 Container Tags : bci/python:3 , bci/python:3-34.24 , bci/python:3.6 , bci/python:3.6-34.24 Container Release : 34.24 Severity : moderate Type : security References : 1205244 1208443 CVE-2022-45061 ----------------------------------------------------------------- The container bci/python was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:549-1 Released: Mon Feb 27 17:35:07 2023 Summary: Security update for python3 Type: security Severity: moderate References: 1205244,1208443,CVE-2022-45061 This update for python3 fixes the following issues: - CVE-2022-45061: Fixed DoS when IDNA decodes extremely long domain names (bsc#1205244). Bugfixes: - Fixed issue where email.generator.py replaces a non-existent header (bsc#1208443). The following package changes have been done: - libpython3_6m1_0-3.6.15-150300.10.40.1 updated - python3-base-3.6.15-150300.10.40.1 updated - python3-3.6.15-150300.10.40.1 updated - python3-devel-3.6.15-150300.10.40.1 updated . Essential revision for bci/python tackles DoS vulnerabilities through improved patches and required protective upgrades.. bci/python security, SUSE update, container patch, moderate security fix. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.