Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-3556

Опубликовано: 12 июн. 2023
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2023-3556: python3 security update (IMPORTANT)

[3.6.8-19.0.1]

  • Remove the 'getfile' feature of pydoc [Orabug: 33182027][CVE-2021-3426]
  • Fix buffer overflow in PyCArg_repr [Orabug: 32551171][CVE-2021-3177]
  • Add Oracle Linux distribution in platform.py [Orabug: 20812544]

[3.6.8-19]

  • Security fix for CVE-2023-24329
  • Fix the test suite support for Expat >= 2.4.5 Resolves: rhbz#2173917

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

python3

3.6.8-19.0.1.el7_9

python3-debug

3.6.8-19.0.1.el7_9

python3-devel

3.6.8-19.0.1.el7_9

python3-idle

3.6.8-19.0.1.el7_9

python3-libs

3.6.8-19.0.1.el7_9

python3-test

3.6.8-19.0.1.el7_9

python3-tkinter

3.6.8-19.0.1.el7_9

Oracle Linux x86_64

python3

3.6.8-19.0.1.el7_9

python3-debug

3.6.8-19.0.1.el7_9

python3-devel

3.6.8-19.0.1.el7_9

python3-idle

3.6.8-19.0.1.el7_9

python3-libs

3.6.8-19.0.1.el7_9

python3-test

3.6.8-19.0.1.el7_9

python3-tkinter

3.6.8-19.0.1.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
redhat
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows ...