Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2021-9562

Опубликовано: 20 нояб. 2021
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2021-9562: python3 security update (IMPORTANT)

[3.6.8-18.0.5]

  • Remove the 'getfile' feature of pydoc [Orabug: 33182027][CVE-2021-3426]

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

python3

3.6.8-18.0.5.el7

python3-debug

3.6.8-18.0.5.el7

python3-devel

3.6.8-18.0.5.el7

python3-idle

3.6.8-18.0.5.el7

python3-libs

3.6.8-18.0.5.el7

python3-test

3.6.8-18.0.5.el7

python3-tkinter

3.6.8-18.0.5.el7

Oracle Linux x86_64

python3

3.6.8-18.0.5.el7

python3-debug

3.6.8-18.0.5.el7

python3-devel

3.6.8-18.0.5.el7

python3-idle

3.6.8-18.0.5.el7

python3-libs

3.6.8-18.0.5.el7

python3-test

3.6.8-18.0.5.el7

python3-tkinter

3.6.8-18.0.5.el7

Связанные CVE

Связанные уязвимости

CVSS3: 5.7
ubuntu
около 4 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
redhat
больше 4 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
nvd
около 4 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7.

CVSS3: 5.7
debian
около 4 лет назад

There's a flaw in Python 3's pydoc. A local or adjacent attacker who d ...

suse-cvrf
около 4 лет назад

Security update for python3