An update that solves one vulnerability can now be installed.. # Security update for python Announcement ID: SUSE-SU-2026:0774-1 Release Date: 2026-03-03T13:18:24Z Rating: low References: * bsc#1229596 Cross-References: * CVE-2024-7592 CVSS scores: * CVE-2024-7592 ( SUSE ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python fixes the following issue: * CVE-2024-7592: uncontrolled CPU resource consumption when in http.cookies module (bsc#1229596). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2026-774=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-774=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libpython2_7-1_0-debuginfo-2.7.18-150000.105.1 * python-demo-2.7.18-150000.105.1 * python-debuginfo-2.7.18-150000.105.1 * python-xml-debuginfo-2.7.18-150000.105.1 * python-tk-debuginfo-2.7.18-150000.105.1 * libpython2_7-1_0-2.7.18-150000.105.1 * python-idle-2.7.18-150000.105.1 * python-2.7.18-150000.105.1 * python-base-2.7.18-150000.105.1 * python-base-debuginfo-2.7.18-150000.105.1 * python-debugsource-2.7.18-150000.105.1 * python-tk-2.7.18-150000.105.1 * python-curses-debuginfo-2.7.18-150000.105.1 *python-gdbm-debuginfo-2.7.18-150000.105.1 * python-gdbm-2.7.18-150000.105.1 * python-xml-2.7.18-150000.105.1 * python-base-debugsource-2.7.18-150000.105.1 * python-curses-2.7.18-150000.105.1 * python-devel-2.7.18-150000.105.1 * openSUSE Leap 15.6 (x86_64) * libpython2_7-1_0-32bit-debuginfo-2.7.18-150000.105.1 * python-base-32bit-2.7.18-150000.105.1 * python-32bit-debuginfo-2.7.18-150000.105.1 * python-base-32bit-debuginfo-2.7.18-150000.105.1 * libpython2_7-1_0-32bit-2.7.18-150000.105.1 * python-32bit-2.7.18-150000.105.1 * openSUSE Leap 15.6 (noarch) * python-doc-pdf-2.7.18-150000.105.1 * python-doc-2.7.18-150000.105.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libpython2_7-1_0-debuginfo-2.7.18-150000.105.1 * python-xml-debuginfo-2.7.18-150000.105.1 * python-debuginfo-2.7.18-150000.105.1 * libpython2_7-1_0-2.7.18-150000.105.1 * python-2.7.18-150000.105.1 * python-base-2.7.18-150000.105.1 * python-base-debuginfo-2.7.18-150000.105.1 * python-debugsource-2.7.18-150000.105.1 * python-curses-debuginfo-2.7.18-150000.105.1 * python-gdbm-debuginfo-2.7.18-150000.105.1 * python-gdbm-2.7.18-150000.105.1 * python-xml-2.7.18-150000.105.1 * python-base-debugsource-2.7.18-150000.105.1 * python-curses-2.7.18-150000.105.1 ## References: * https://www.suse.com/security/cve/CVE-2024-7592.html * https://bugzilla.suse.com/show_bug.cgi?id=1229596 . An update for SUSE addresses low-severity Python issue with CVE-2024-7592 impacting resource management.. Python CVE fix, SUSE update, resource management issue. . Severity: Low. LinuxSecurity.com Team
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6f77f6c77a 2025-03-01 01:38:57.010399+00:00 -------------------------------------------------------------------------------- Name : cutter-re Product : Fedora 40 Version : 2.3.4 Release : 6.fc40 URL : https://cutter.re/ Summary : GUI for Rizin reverse engineering framework Description : Cutter is a Qt and C++ GUI for Rizin. Its goal is making an advanced, customizable and FOSS reverse-engineering platform while keeping the user experience at mind. Cutter is created by reverse engineers for reverse engineers. -------------------------------------------------------------------------------- Update Information: CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code rizin 0.7.2 / cutter-re 2.3.4 (fix changelog) rizin 0.7.2 / cutter-re 2.3.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 16 2025 Fedora Release Engineering - 2.3.4-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Jan 1 2025 Michal Ambroz - 2.3.4-5 - Rebuild with new version of rizin 0.7.4 * Wed Jul 17 2024 Fedora Release Engineering - 2.3.4-4 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333933 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333933 [ 2 ] Bug #2333934 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2333934 [ 3 ] Bug #2340020 - cutter-re: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340020 [ 4 ] Bug #2346253 - Non-responsive maintainer check for ret2libc https://bugzilla.redhat.com/show_bug.cgi?id=2346253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6f77f6c77a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1290a47fff 2025-03-01 01:22:54.667719+00:00 -------------------------------------------------------------------------------- Name : cutter-re Product : Fedora 41 Version : 2.3.4 Release : 6.fc41 URL : https://cutter.re/ Summary : GUI for Rizin reverse engineering framework Description : Cutter is a Qt and C++ GUI for Rizin. Its goal is making an advanced, customizable and FOSS reverse-engineering platform while keeping the user experience at mind. Cutter is created by reverse engineers for reverse engineers. -------------------------------------------------------------------------------- Update Information: CVE-2023-40022 rizin: Integer Overflow in C++ demangler logic CVE-2024-31669 rizin: Uncontrolled Resource Consumption via bin_pe_parse_imports CVE-2024-31670 rizin: buffer overflow via create_cache_bins CVE-2024-31668 rizin: improper neutralization of special elements via meta_set function CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 16 2025 Fedora Release Engineering - 2.3.4-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild * Wed Jan 1 2025 Michal Ambroz - 2.3.4-5 - Rebuild with new version of rizin 0.7.4 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2333933 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2333933 [ 2 ] Bug #2333934 - CVE-2024-53256 rizin: Rizin has a command injection via RzBinInfo bclass due legacy code [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2333934 [ 3 ] Bug #2340020 - cutter-re: FTBFS in Fedora rawhide/f42 https://bugzilla.redhat.com/show_bug.cgi?id=2340020 [ 4 ] Bug #2346253 - Non-responsive maintainer check for ret2libc https://bugzilla.redhat.com/show_bug.cgi?id=2346253 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1290a47fff' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.