* CVE-2019-20907: Avoid infinite loop in the tarfile module * CVE-2020-14422: Resolve hash collisions for IPv4Interface and IPv6Interface * CVE-2020-26116: HTTP request method CRLF injection in httplib This update brings Fedora 32's python34 in sync with the EPEL7 package.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-d30881c970 2020-10-16 15:18:47.312128 --------------------------------------------------------------------------------Name : python34 Product : Fedora 32 Version : 3.4.10 Release : 11.fc32 URL : https://www.python.org/ Summary : Version 3.4 of the Python programming language Description : Python 3.4 package for developers. This package exists to allow developers to test their code against an older version of Python. This is not a full Python stack and if you wish to run your applications with Python 3.4, see other distributions that support it, such as CentOS or RHEL with Software Collections. --------------------------------------------------------------------------------Update Information: * CVE-2019-20907: Avoid infinite loop in the tarfile module * CVE-2020-14422: Resolve hash collisions for IPv4Interface and IPv6Interface * CVE-2020-26116: HTTP request method CRLF injection in httplib This update brings Fedora 32's python34 in sync with the EPEL7 package. --------------------------------------------------------------------------------ChangeLog: * Wed Sep 30 2020 Petr Viktorin - 3.4.10-11 - CVE-2019-20907: Avoid infinite loop in the tarfile module - CVE-2020-14422: Resolve hash collisions for IPv4Interface and IPv6Interface - CVE-2020-26116: HTTP request method CRLF injection in httplib - update test certs and keys --------------------------------------------------------------------------------References: [ 1 ] Bug #1854938 - CVE-2020-14422 python34: python: Denial of service via inefficiency in IPv{4,6}Interface classes [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1854938 [ 2 ] Bug #1856491 - CVE-2019-20907 python34: python: infinite loop in the tarfile module via a craft TAR archive [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1856491 [ 3 ] Bug #1883245 - CVE-2020-26116 python34: python: CRLF injection via HTTP request method in httplib/http.client [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1883245 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-d30881c970' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Fix CVE-2019-16056 (rhbz#1750457) ---- Fix CVE-2019-10160 (rhbz#1718867). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-2b1f72899a 2019-09-19 01:28:48.404470 --------------------------------------------------------------------------------Name : python34 Product : Fedora 30 Version : 3.4.10 Release : 3.fc30 URL : https://www.python.org/ Summary : Version 3.4 of the Python programming language Description : Python 3.4 package for developers. This package exists to allow developers to test their code against an older version of Python. This is not a full Python stack and if you wish to run your applications with Python 3.4, see other distributions that support it, such as CentOS or RHEL with Software Collections. --------------------------------------------------------------------------------Update Information: Fix CVE-2019-16056 (rhbz#1750457) ---- Fix CVE-2019-10160 (rhbz#1718867) --------------------------------------------------------------------------------ChangeLog: * Mon Sep 9 2019 Charalampos Stratakis - 3.4.10-3 - Fix CVE-2019-16056 (rhbz#1750457) * Thu Sep 5 2019 Charalampos Stratakis - 3.4.10-2 - Fix CVE-2019-10160 (rhbz#1718867) --------------------------------------------------------------------------------References: [ 1 ] Bug #1750457 - CVE-2019-16056 python34: python: email.utils.parseaddr wrongly parses email addresses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1750457 [ 2 ] Bug #1718867 - CVE-2019-10160 python34: python: regression of CVE-2019-9636 due to functional fix to allow port numbers in netloc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1718867 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-2b1f72899a' at the command line. For more information, refer to thednf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2017-1000158. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a41f6a8078 2017-12-19 18:22:41.464505 --------------------------------------------------------------------------------Name : python34 Product : Fedora 27 Version : 3.4.7 Release : 2.fc27 URL : https://www.python.org/ Summary : Version 3.4 of the Python programming language Description : Python 3.4 package for developers. This package exists to allow developers to test their code against an older version of Python. This is not a full Python stack and if you wish to run your applications with Python 3.4, see other distributions that support it, such as CentOS or RHEL with Software Collections. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-1000158 --------------------------------------------------------------------------------References: [ 1 ] Bug #1519595 - CVE-2017-1000158 python: Integer overflow in PyString_DecodeEscape results in heap-base buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=1519595 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade python34' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.