Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
**Update to 3.8.9.** [Full changelog.](https://docs.python.org/release/3.8.9/whatsnew/changelog.html) Contains security fix for CVE-2021-3426. ---- **Update to 3.8.8.** [Full changelog.](https://docs.python.org/release/3.8.8/whatsnew/changelog.html) Contains security fix for CVE-2021-23336.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-b6b6093b3a 2021-04-23 15:04:50.170419 --------------------------------------------------------------------------------Name : python3-docs Product : Fedora 32 Version : 3.8.9 Release : 1.fc32 URL : https://www.python.org/ Summary : Documentation for the Python 3 programming language Description : The python3-docs package contains documentation on the Python 3 programming language and interpreter. --------------------------------------------------------------------------------Update Information: **Update to 3.8.9.** [Full changelog.](https://docs.python.org/release/3.8.9/whatsnew/changelog.html) Contains security fix for CVE-2021-3426. ---- **Update to 3.8.8.** [Full changelog.](https://docs.python.org/release/3.8.8/whatsnew/changelog.html) Contains security fix for CVE-2021-23336. --------------------------------------------------------------------------------ChangeLog: * Tue Apr 6 2021 Tomas Hrnciar - 3.8.9-1 - Update to 3.8.9 --------------------------------------------------------------------------------References: [ 1 ] Bug #1928904 - CVE-2021-23336 python: Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters https://bugzilla.redhat.com/show_bug.cgi?id=1928904 [ 2 ] Bug #1935913 - CVE-2021-3426 python: information disclosure via pydoc https://bugzilla.redhat.com/show_bug.cgi?id=1935913 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2021-b6b6093b3a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Three security issues have been discovered in python3.5: CVE-2021-3177 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2619-1
Updated python-bottle packages fix security vulnerability: python-bottle before 0.12.19 is vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the . MGASA-2021-0171 - Updated python-bottle packages fix security vulnerability Publication date: 02 Apr 2021 URL: https://advisories.mageia.org/MGASA-2021-0171.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-28473 Updated python-bottle packages fix security vulnerability: python-bottle before 0.12.19 is vulnerable to Web Cache Poisoning by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter (CVE-2020-28473). References: - https://bugs.mageia.org/show_bug.cgi?id=28219 - https://lists.debian.org/debian-lts-announce/2021/01/msg00019.html - https://www.cve.org/CVERecord?id=CVE-2020-28473 SRPMS: - 7/core/python-bottle-0.12.16-1.1.mga7 . MGASA-2021-0171 - Updated python-bottle packages fix security vulnerability Publication date: 02 Apr. python-bottle, updated, packages, security, vulnerability, vulnerabl. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python3 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0947-1 Rating: moderate References: #1182379 Cross-References: CVE-2021-23336 CVSS scores: CVE-2021-23336 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H CVE-2021-23336 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H Affected Products: SUSE MicroOS 5.0 SUSE Linux Enterprise Module for Development Tools 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python3 fixes the following issues: - python36 was updated to 3.6.13 - CVE-2021-23336: Fixed a potential web cache poisoning by using a semicolon in query parameters use of semicolon as a query string separator (bsc#1182379). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE MicroOS 5.0: zypper in -t patch SUSE-SUSE-MicroOS-5.0-2021-947=1 - SUSE Linux Enterprise Module for Development Tools 15-SP2: zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP2-2021-947=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2021-947=1 Package List: - SUSE MicroOS 5.0 (aarch64 x86_64): libpython3_6m1_0-3.6.13-3.78.1 libpython3_6m1_0-debuginfo-3.6.13-3.78.1 python3-3.6.13-3.78.1 python3-base-3.6.13-3.78.1 python3-base-debuginfo-3.6.13-3.78.1 python3-core-debugsource-3.6.13-3.78.1 python3-debuginfo-3.6.13-3.78.1 python3-debugsource-3.6.13-3.78.1 - SUSE Linux Enterprise Module for Development Tools 15-SP2 (aarch64 ppc64le s390x x86_64): python3-tools-3.6.13-3.78.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): libpython3_6m1_0-3.6.13-3.78.1 libpython3_6m1_0-debuginfo-3.6.13-3.78.1 python3-3.6.13-3.78.1 python3-base-3.6.13-3.78.1 python3-curses-3.6.13-3.78.1 python3-curses-debuginfo-3.6.13-3.78.1 python3-dbm-3.6.13-3.78.1 python3-dbm-debuginfo-3.6.13-3.78.1 python3-debuginfo-3.6.13-3.78.1 python3-debugsource-3.6.13-3.78.1 python3-devel-3.6.13-3.78.1 python3-devel-debuginfo-3.6.13-3.78.1 python3-idle-3.6.13-3.78.1 python3-tk-3.6.13-3.78.1 python3-tk-debuginfo-3.6.13-3.78.1 References: https://www.suse.com/security/cve/CVE-2021-23336.html https://bugzilla.suse.com/1182379 . An essential patch has been released for python3 targeting vulnerabilities linked to web cache poisoning. Discover the steps to implement this correction.. SUSE MicroOS Update, Python3 Security Patch, Web Cache Poisoning. . LinuxSecurity.com Team
Update to python3-3.9.2, see https://docs.python.org/3/whatsnew/3.9.html for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-e525e48886 2021-03-19 19:51:22.365691 --------------------------------------------------------------------------------Name : mingw-python3 Product : Fedora 34 Version : 3.9.2 Release : 2.fc34 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 library. --------------------------------------------------------------------------------Update Information: Update to python3-3.9.2, see https://docs.python.org/3/whatsnew/3.9.html for details. --------------------------------------------------------------------------------ChangeLog: * Sat Feb 27 2021 Sandro Mani - 3.9.2-2 - Pass --enable-loadable-sqlite-extensions --------------------------------------------------------------------------------References: [ 1 ] Bug #1928912 - CVE-2021-23336 mingw-python3: python: Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1928912 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-e525e48886' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
update to 3.1.7, fix CVE-2021-23336 (rhbz#1931542). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-e22bb0e548 2021-03-19 19:51:22.365268 --------------------------------------------------------------------------------Name : python-django Product : Fedora 34 Version : 3.1.7 Release : 1.fc34 URL : https://www.djangoproject.com/ Summary : A high-level Python Web framework Description : Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. --------------------------------------------------------------------------------Update Information: update to 3.1.7, fix CVE-2021-23336 (rhbz#1931542) --------------------------------------------------------------------------------ChangeLog: * Fri Mar 5 2021 Matthias Runge - 3.1.7-1 - update to 3.1.7, fix CVE-2021-23336 (rhbz#1931542) --------------------------------------------------------------------------------References: [ 1 ] Bug #1928904 - CVE-2021-23336 python: Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters https://bugzilla.redhat.com/show_bug.cgi?id=1928904 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-e22bb0e548' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announcemailing list --
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for python ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0794-1 Rating: moderate References: #1182379 Cross-References: CVE-2019-18348 CVE-2021-23336 CVSS scores: CVE-2019-18348 (NVD) : 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2019-18348 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2021-23336 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H CVE-2021-23336 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Workstation Extension 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for python fixes the following issues: - python27 was upgraded to 2.7.18 - CVE-2021-23336: Fixed a potential web cache poisoning by using a semicolon in query parameters use of semicolon as a query string separator(bsc#1182379). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-794=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-794=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-794=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-794=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2021-794=1 - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2021-794=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-794=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-794=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2021-794=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-794=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-794=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-794=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-794=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2021-794=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-794=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-794=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE OpenStack Cloud Crowbar 9 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE OpenStack Cloud Crowbar 8 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE OpenStack Cloud 9 (x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE OpenStack Cloud 9 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE OpenStack Cloud 8 (x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE OpenStack Cloud 8 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE OpenStack Cloud 7 (s390x x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE OpenStack Cloud 7 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 python-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 python-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP12-SP3 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 python-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 python-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP5 (s390x x86_64): libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP5 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 python-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (s390x x86_64): libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 python-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x x86_64): libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server12-SP3-BCL (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 python-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - HPE Helion Openstack 8 (x86_64): libpython2_7-1_0-2.7.18-28.67.1 libpython2_7-1_0-32bit-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-2.7.18-28.67.1 libpython2_7-1_0-debuginfo-32bit-2.7.18-28.67.1 python-2.7.18-28.67.1 python-32bit-2.7.18-28.67.1 python-base-2.7.18-28.67.1 python-base-32bit-2.7.18-28.67.1 python-base-debuginfo-2.7.18-28.67.1 python-base-debuginfo-32bit-2.7.18-28.67.1 python-base-debugsource-2.7.18-28.67.1 python-curses-2.7.18-28.67.1 python-curses-debuginfo-2.7.18-28.67.1 python-debuginfo-2.7.18-28.67.1 python-debuginfo-32bit-2.7.18-28.67.1 python-debugsource-2.7.18-28.67.1 python-demo-2.7.18-28.67.1 python-devel-2.7.18-28.67.1 python-gdbm-2.7.18-28.67.1 python-gdbm-debuginfo-2.7.18-28.67.1 python-idle-2.7.18-28.67.1 python-tk-2.7.18-28.67.1 python-tk-debuginfo-2.7.18-28.67.1 python-xml-2.7.18-28.67.1 python-xml-debuginfo-2.7.18-28.67.1 - HPE Helion Openstack 8 (noarch): python-doc-2.7.18-28.67.1 python-doc-pdf-2.7.18-28.67.1 References: https://www.suse.com/security/cve/CVE-2019-18348.html https://www.suse.com/security/cve/CVE-2021-23336.html https://bugzilla.suse.com/1182379 . SUSE's Security Update offers a moderate fix for Python flaws, mitigating risks associated with possible web cache poisoning issues.. SUSE Python Update, Web Cache Poisoning, Python Update Fix. . LinuxSecurity.com Team
Update to python3-3.9.2, see https://docs.python.org/3/whatsnew/3.9.html for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-b76ede8f4d 2021-03-15 01:17:22.121076 --------------------------------------------------------------------------------Name : mingw-python3 Product : Fedora 33 Version : 3.9.2 Release : 1.fc33 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 library. --------------------------------------------------------------------------------Update Information: Update to python3-3.9.2, see https://docs.python.org/3/whatsnew/3.9.html for details. --------------------------------------------------------------------------------ChangeLog: * Mon Feb 22 2021 Sandro Mani - 3.9.2-1 - Update to 3.9.2 * Mon Feb 15 2021 Sandro Mani - 3.9.1-4 - MACHDEP=win32 * Tue Jan 26 2021 Fedora Release Engineering - 3.9.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1928912 - CVE-2021-23336 mingw-python3: python: Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1928912 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-b76ede8f4d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.