Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-3780

Опубликовано: 08 июл. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-3780: python27:2.7 security update (IMPORTANT)

babel [2.5.1-10]

  • Fix CVE-2021-20095 Resolves: rhbz#1955615

Cython [0.28.1-7]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

numpy [1:1.14.2-16]

  • Fix include path
  • Related: rhbz#1907601

pytest python2 [2.7.18-13.0.1.1]

  • Fix for CVE-2023-24329
  • Add missing part of fix for CVE-2022-45061

python2-pip [9.0.3-19]

  • Remove bundled windows executables
  • Resolves: rhbz#2006792

python2-rpm-macros python2-setuptools [39.0.1-13]

  • When building for Flatpak inclusion, build in bootstrap mode Resolves: rhbz#1907597

python2-six [1.11.0-6]

  • Rename component name to python2-six, clean specfile and remove bconds
  • Resolves: rhbz#1908300

python-attrs python-backports [1.0-16]

  • Update python macros to python2 versioned macros
  • Issue found when rebuilding the python27 module to include CVE fixes
  • Related: rhbz#1883890 rhbz#1883258

python-backports-ssl_match_hostname [3.5.0.1-12]

  • Remove unversioned Provides
  • Resolves: rhbz#1908300

python-chardet [3.0.4-10]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-coverage [4.5.1-4]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-dns python-docs [2.7.16-2]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-docutils python-funcsigs python-idna [2.5-7]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-ipaddress python-jinja2 [2.10-9]

  • Fix CVE-2020-28493: ReDOS vulnerability due to the sub-pattern Resolves: rhbz#1928707

python-lxml [4.2.3-6]

  • Security fix for CVE-2021-43818 Resolves: rhbz#2032569

python-markupsafe [0.23-19]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-mock python-nose python-pluggy python-psycopg2 [2.7.5-7]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-py python-pygments python-pymongo python-PyMySQL [0.8.0-10]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-pysocks [1.6.8-6]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

python-pytest-mock python-requests [2.20.0-3]

  • Properly handle default ports when stripping the authorization header Resolves: rhbz#1762422

python-setuptools_scm python-sqlalchemy python-urllib3 [1.24.2-3]

  • Update RECENT_DATE dynamically Related: rhbz#1883890 rhbz#1761380

python-virtualenv python-wheel [1:0.31.1-3]

  • Adjusted the postun scriptlets to enable upgrading to RHEL 9
  • Resolves: rhbz#1933055

pytz [2017.2-12]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

PyYAML [3.12-16]

  • Bumping due to problems with modular RPM upgrade path
  • Resolves: rhbz#1695587

scipy

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module python27:2.7 is enabled

babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python-nose-docs

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python-psycopg2-doc

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python-sqlalchemy-doc

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-Cython

0.28.1-7.module+el8.3.0+7833+4aaf98ce

python2-PyMySQL

0.8.0-10.module+el8.3.0+7833+4aaf98ce

python2-attrs

17.4.0-10.module+el8.3.0+7833+4aaf98ce

python2-babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python2-backports

1.0-16.module+el8.4.0+20050+79c7b4ee

python2-backports-ssl_match_hostname

3.5.0.1-12.module+el8.4.0+20050+79c7b4ee

python2-bson

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-chardet

3.0.4-10.module+el8.3.0+7833+4aaf98ce

python2-coverage

4.5.1-4.module+el8.3.0+7833+4aaf98ce

python2-debug

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-devel

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-dns

1.15.0-10.module+el8.3.0+7833+4aaf98ce

python2-docs

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docs-info

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docutils

0.14-12.module+el8.3.0+7833+4aaf98ce

python2-funcsigs

1.0.2-13.module+el8.3.0+7833+4aaf98ce

python2-idna

2.5-7.module+el8.3.0+7833+4aaf98ce

python2-ipaddress

1.0.18-6.module+el8.3.0+7833+4aaf98ce

python2-jinja2

2.10-9.module+el8.5.0+20361+8a9d3d27

python2-libs

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-lxml

4.2.3-6.module+el8.6.0+20550+a85dc526

python2-markupsafe

0.23-19.module+el8.3.0+7833+4aaf98ce

python2-mock

2.0.0-13.module+el8.3.0+7833+4aaf98ce

python2-nose

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python2-numpy

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-doc

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-f2py

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-pip

9.0.3-19.module+el8.6.0+20550+a85dc526

python2-pip-wheel

9.0.3-19.module+el8.6.0+20550+a85dc526

python2-pluggy

0.6.0-8.module+el8.3.0+7833+4aaf98ce

python2-psycopg2

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-debug

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-tests

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-py

1.5.3-6.module+el8.3.0+7833+4aaf98ce

python2-pygments

2.2.0-22.module+el8.5.0+20361+8a9d3d27

python2-pymongo

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pymongo-gridfs

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pysocks

1.6.8-6.module+el8.3.0+7833+4aaf98ce

python2-pytest

3.4.2-13.module+el8.3.0+7833+4aaf98ce

python2-pytest-mock

1.9.0-4.module+el8.3.0+7833+4aaf98ce

python2-pytz

2017.2-12.module+el8.3.0+7833+4aaf98ce

python2-pyyaml

3.12-16.module+el8.3.0+7833+4aaf98ce

python2-requests

2.20.0-3.module+el8.3.0+7833+4aaf98ce

python2-rpm-macros

3-38.module+el8.3.0+7833+4aaf98ce

python2-scipy

1.0.0-21.module+el8.5.0+20361+8a9d3d27

python2-setuptools

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools-wheel

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools_scm

1.15.7-6.module+el8.3.0+7833+4aaf98ce

python2-six

1.11.0-6.module+el8.4.0+20050+79c7b4ee

python2-sqlalchemy

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2-test

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-tkinter

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-tools

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-urllib3

1.24.2-3.module+el8.4.0+20050+79c7b4ee

python2-virtualenv

15.1.0-22.module+el8.8.0+21096+ceeb3972

python2-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

python2-wheel-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

Oracle Linux x86_64

Module python27:2.7 is enabled

babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python-nose-docs

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python-psycopg2-doc

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python-sqlalchemy-doc

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-Cython

0.28.1-7.module+el8.3.0+7833+4aaf98ce

python2-PyMySQL

0.8.0-10.module+el8.3.0+7833+4aaf98ce

python2-attrs

17.4.0-10.module+el8.3.0+7833+4aaf98ce

python2-babel

2.5.1-10.module+el8.5.0+20361+8a9d3d27

python2-backports

1.0-16.module+el8.4.0+20050+79c7b4ee

python2-backports-ssl_match_hostname

3.5.0.1-12.module+el8.4.0+20050+79c7b4ee

python2-bson

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-chardet

3.0.4-10.module+el8.3.0+7833+4aaf98ce

python2-coverage

4.5.1-4.module+el8.3.0+7833+4aaf98ce

python2-debug

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-devel

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-dns

1.15.0-10.module+el8.3.0+7833+4aaf98ce

python2-docs

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docs-info

2.7.16-2.module+el8.3.0+7833+4aaf98ce

python2-docutils

0.14-12.module+el8.3.0+7833+4aaf98ce

python2-funcsigs

1.0.2-13.module+el8.3.0+7833+4aaf98ce

python2-idna

2.5-7.module+el8.3.0+7833+4aaf98ce

python2-ipaddress

1.0.18-6.module+el8.3.0+7833+4aaf98ce

python2-jinja2

2.10-9.module+el8.5.0+20361+8a9d3d27

python2-libs

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-lxml

4.2.3-6.module+el8.6.0+20550+a85dc526

python2-markupsafe

0.23-19.module+el8.3.0+7833+4aaf98ce

python2-mock

2.0.0-13.module+el8.3.0+7833+4aaf98ce

python2-nose

1.3.7-31.module+el8.5.0+20361+8a9d3d27

python2-numpy

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-doc

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-numpy-f2py

1.14.2-16.module+el8.4.0+20050+79c7b4ee

python2-pip

9.0.3-19.module+el8.6.0+20550+a85dc526

python2-pip-wheel

9.0.3-19.module+el8.6.0+20550+a85dc526

python2-pluggy

0.6.0-8.module+el8.3.0+7833+4aaf98ce

python2-psycopg2

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-debug

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-psycopg2-tests

2.7.5-7.module+el8.3.0+7833+4aaf98ce

python2-py

1.5.3-6.module+el8.3.0+7833+4aaf98ce

python2-pygments

2.2.0-22.module+el8.5.0+20361+8a9d3d27

python2-pymongo

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pymongo-gridfs

3.7.0-1.module+el8.5.0+20361+8a9d3d27

python2-pysocks

1.6.8-6.module+el8.3.0+7833+4aaf98ce

python2-pytest

3.4.2-13.module+el8.3.0+7833+4aaf98ce

python2-pytest-mock

1.9.0-4.module+el8.3.0+7833+4aaf98ce

python2-pytz

2017.2-12.module+el8.3.0+7833+4aaf98ce

python2-pyyaml

3.12-16.module+el8.3.0+7833+4aaf98ce

python2-requests

2.20.0-3.module+el8.3.0+7833+4aaf98ce

python2-rpm-macros

3-38.module+el8.3.0+7833+4aaf98ce

python2-scipy

1.0.0-21.module+el8.5.0+20361+8a9d3d27

python2-setuptools

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools-wheel

39.0.1-13.module+el8.4.0+20050+79c7b4ee

python2-setuptools_scm

1.15.7-6.module+el8.3.0+7833+4aaf98ce

python2-six

1.11.0-6.module+el8.4.0+20050+79c7b4ee

python2-sqlalchemy

1.3.2-2.module+el8.3.0+7833+4aaf98ce

python2-test

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-tkinter

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-tools

2.7.18-13.0.1.module+el8.8.0+21096+ceeb3972.1

python2-urllib3

1.24.2-3.module+el8.4.0+20050+79c7b4ee

python2-virtualenv

15.1.0-22.module+el8.8.0+21096+ceeb3972

python2-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

python2-wheel-wheel

0.31.1-3.module+el8.5.0+20361+8a9d3d27

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
redhat
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
nvd
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.

CVSS3: 7.5
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 7.5
debian
больше 2 лет назад

An issue in the urllib.parse component of Python before 3.11.4 allows ...