Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-4151

Опубликовано: 16 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2021-4151: python27:2.7 security update (MODERATE)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module python27:2.7 is enabled

babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python-nose-docs

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python-psycopg2-doc

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python-sqlalchemy-doc

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-Cython

0.28.1-7.module+el8.3.0+7833+4aaf98ce

python2-PyMySQL

0.8.0-10.module+el8.3.0+7833+4aaf98ce

python2-attrs

17.4.0-10.module+el8.3.0+7833+4aaf98ce

python2-babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python2-backports

1.0-16.module+el8.4.0+20050+79c7b4ee

python2-backports-ssl_match_hostname

3.5.0.1-12.module+el8.4.0+20050+79c7b4ee

python2-bson

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-chardet

3.0.4-10.module+el8.3.0+7833+4aaf98ce

python2-coverage

4.5.1-4.module+el8.3.0+7833+4aaf98ce

python2-debug

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-devel

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-dns

1.15.0-10.module+el8.3.0+7833+4aaf98ce

python2-docs

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docs-info

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docutils

0.14-12.module+el8.3.0+7833+4aaf98ce

python2-funcsigs

1.0.2-13.module+el8.3.0+7833+4aaf98ce

python2-idna

2.5-7.module+el8.3.0+7833+4aaf98ce

python2-ipaddress

1.0.18-6.module+el8.3.0+7833+4aaf98ce

python2-jinja2

2.10-9.module+el8.5.0+20361+8a9d3d27

python2-libs

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-lxml

4.2.3-5.module+el8.5.0+20361+8a9d3d27

python2-markupsafe

0.23-19.module+el8.3.0+7833+4aaf98ce

python2-mock

2.0.0-13.module+el8.3.0+7833+4aaf98ce

python2-nose

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python2-numpy

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-doc

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-f2py

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-pip

9.0.3-18.module+el8.3.0+7833+4aaf98ce

python2-pip-wheel

9.0.3-18.module+el8.3.0+7833+4aaf98ce

python2-pluggy

0.6.0-8.module+el8.3.0+7833+4aaf98ce

python2-psycopg2

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-debug

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-tests

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-py

1.5.3-6.module+el8.3.0+7833+4aaf98ce

python2-pygments

2.2.0-22.module+el8.5.0+20361+8a9d3d27

python2-pymongo

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pymongo-gridfs

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pysocks

1.6.8-6.module+el8.3.0+7833+4aaf98ce

python2-pytest

3.4.2-13.module+el8.3.0+7833+4aaf98ce

python2-pytest-mock

1.9.0-4.module+el8.3.0+7833+4aaf98ce

python2-pytz

2017.2-12.module+el8.3.0+7833+4aaf98ce

python2-pyyaml

3.12-16.module+el8.3.0+7833+4aaf98ce

python2-requests

2.20.0-3.module+el8.3.0+7833+4aaf98ce

python2-rpm-macros

3-38.module+el8.3.0+7833+4aaf98ce

python2-scipy

1.0.0-21.module+el8.5.0+20361+8a9d3d27

python2-setuptools

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools-wheel

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools_scm

1.15.7-6.module+el8.3.0+7833+4aaf98ce

python2-six

1.11.0-6.module+el8.4.0+20050+79c7b4ee

python2-sqlalchemy

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2-test

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-tkinter

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-tools

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-urllib3

1.24.2-3.module+el8.4.0+20050+79c7b4ee

python2-virtualenv

15.1.0-21.module+el8.5.0+20361+8a9d3d27

python2-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

python2-wheel-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

Oracle Linux x86_64

Module python27:2.7 is enabled

babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python-nose-docs

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python-psycopg2-doc

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python-sqlalchemy-doc

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-Cython

0.28.1-7.module+el8.3.0+7833+4aaf98ce

python2-PyMySQL

0.8.0-10.module+el8.3.0+7833+4aaf98ce

python2-attrs

17.4.0-10.module+el8.3.0+7833+4aaf98ce

python2-babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python2-backports

1.0-16.module+el8.4.0+20050+79c7b4ee

python2-backports-ssl_match_hostname

3.5.0.1-12.module+el8.4.0+20050+79c7b4ee

python2-bson

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-chardet

3.0.4-10.module+el8.3.0+7833+4aaf98ce

python2-coverage

4.5.1-4.module+el8.3.0+7833+4aaf98ce

python2-debug

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-devel

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-dns

1.15.0-10.module+el8.3.0+7833+4aaf98ce

python2-docs

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docs-info

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docutils

0.14-12.module+el8.3.0+7833+4aaf98ce

python2-funcsigs

1.0.2-13.module+el8.3.0+7833+4aaf98ce

python2-idna

2.5-7.module+el8.3.0+7833+4aaf98ce

python2-ipaddress

1.0.18-6.module+el8.3.0+7833+4aaf98ce

python2-jinja2

2.10-9.module+el8.5.0+20361+8a9d3d27

python2-libs

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-lxml

4.2.3-5.module+el8.5.0+20361+8a9d3d27

python2-markupsafe

0.23-19.module+el8.3.0+7833+4aaf98ce

python2-mock

2.0.0-13.module+el8.3.0+7833+4aaf98ce

python2-nose

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python2-numpy

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-doc

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-f2py

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-pip

9.0.3-18.module+el8.3.0+7833+4aaf98ce

python2-pip-wheel

9.0.3-18.module+el8.3.0+7833+4aaf98ce

python2-pluggy

0.6.0-8.module+el8.3.0+7833+4aaf98ce

python2-psycopg2

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-debug

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-tests

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-py

1.5.3-6.module+el8.3.0+7833+4aaf98ce

python2-pygments

2.2.0-22.module+el8.5.0+20361+8a9d3d27

python2-pymongo

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pymongo-gridfs

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pysocks

1.6.8-6.module+el8.3.0+7833+4aaf98ce

python2-pytest

3.4.2-13.module+el8.3.0+7833+4aaf98ce

python2-pytest-mock

1.9.0-4.module+el8.3.0+7833+4aaf98ce

python2-pytz

2017.2-12.module+el8.3.0+7833+4aaf98ce

python2-pyyaml

3.12-16.module+el8.3.0+7833+4aaf98ce

python2-requests

2.20.0-3.module+el8.3.0+7833+4aaf98ce

python2-rpm-macros

3-38.module+el8.3.0+7833+4aaf98ce

python2-scipy

1.0.0-21.module+el8.5.0+20361+8a9d3d27

python2-setuptools

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools-wheel

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools_scm

1.15.7-6.module+el8.3.0+7833+4aaf98ce

python2-six

1.11.0-6.module+el8.4.0+20050+79c7b4ee

python2-sqlalchemy

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2-test

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-tkinter

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-tools

2.7.18-7.0.1.module+el8.5.0+20361+8a9d3d27

python2-urllib3

1.24.2-3.module+el8.4.0+20050+79c7b4ee

python2-virtualenv

15.1.0-21.module+el8.5.0+20361+8a9d3d27

python2-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

python2-wheel-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

Связанные уязвимости

rocky
больше 3 лет назад

Moderate: python27:2.7 security update

rocky
больше 3 лет назад

Moderate: python38:3.8 and python38-devel:3.8 security update

oracle-oval
больше 3 лет назад

ELSA-2021-4162: python38:3.8 and python38-devel:3.8 security update (MODERATE)

oracle-oval
около 4 лет назад

ELSA-2021-1633: python3 security update (MODERATE)

CVSS3: 5.9
ubuntu
больше 4 лет назад

The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter.