Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-5998

Опубликовано: 25 окт. 2023
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2023-5998: python39:3.9 and python39-devel:3.9 security update (IMPORTANT)

Cython [0.29.21-5]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

mod_wsgi [4.7.1-5]

  • Core dumped upon file upload >= 1GB Resolves: rhbz#2125172

numpy [1.19.4-3]

  • Adjusted the postun scriptlets to enable upgrading to RHEL 9
  • Resolves: rhbz#1933055

pybind11 [2.7.1-1]

  • Update to 2.7.1
  • Resolves: rhbz#2000212

pytest [6.0.2-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[6.0.2-1]

  • Update to 6.0.2.

[6.0.1-1]

  • Update to 6.0.1 (#1862097)

[6.0.0~rc1-1]

  • Update to 6.0.0rc1

[5.4.3-2]

[5.4.3-1]

  • Update to 5.4.3.

[5.4.2-1]

  • Update to 5.4.2 (#1707986)

[4.6.10-3]

  • Rebuilt for Python 3.9

[4.6.10-2]

  • Bootstrap for Python 3.9

[4.6.10-1]

  • Update to 4.6.10.

[4.6.9-2]

[4.6.9-1]

  • Update to 4.6.9.

[4.6.8-1]

  • Update to 4.6.8.

[4.6.7-1]

  • Update to 4.6.7

python39 python3x-pip [20.2.4-7]

  • Remove bundled windows executables
  • Resolves: rhbz#2006790

python3x-setuptools [50.3.2-4]

  • Adjusted the postun scriptlets to enable upgrading to RHEL 9
  • Resolves: rhbz#1933055

python3x-six [1.15.0-3]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[1.15.0-2]

[1.15.0-1]

  • Update to 1.15.0 (#1838702)

[1.14.0-4]

  • Rebuilt for Python 3.9

[1.14.0-3]

  • Bootstrap for Python 3.9

[1.14.0-2]

[1.14.0-1]

  • Update to 1.14.0 (#1768982) for Python 3.9 support (#1788494)
  • Drop old obsoletes for platform-python-six

python-attrs [20.3.0-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[20.3.0-1]

  • Update to 20.3.0 (#1894866)

[20.2.0-1]

  • Update to 20.2.0 (#1876063)

[20.1.0-1]

  • Update to 20.1.0 (#1870794)

[19.3.0-5]

[19.3.0-4]

  • Rebuilt for Python 3.9

python-cffi [1.14.3-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[1.14.3-1]

  • Update to 1.14.3

[1.14.2-1]

  • Update to 1.14.2 (#1869032)

[1.14.1-1]

  • Update to 1.14.1
  • Fixes: rhbz#1860698
  • Fixes: rhbz#1865276

[1.14.0-2]

  • Rebuilt for Python 3.9

[1.14.0]

  • Update to 1.14.0 (#1800646)

python-chardet python-cryptography [3.3.1-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[3.3.1-1]

  • Update to 3.3.1 (#1905756)

[3.2.1-1]

  • Update to 3.2.1 (#1892153)

[3.2-1]

  • Update to 3.2 (#1891378)

[3.1-1]

  • Update to 3.1 (#1872978)

[3.0-2]

[3.0-1]

  • Update to 3.0 (#185897)

[2.9-3]

  • Rebuilt for Python 3.9

[2.9-2]

  • add source file verification

[2.9-1]

  • Update to 2.9 (#1820348)

python-idna [2.10-3]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[2.10-2]

[2.10-1]

  • Update to 2.10 (#1851653)

[2.9-2]

  • Rebuilt for Python 3.9

[2.9-1]

  • Update to 2.9 (#1803654)

python-iniconfig [1.1.1-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Revert usage of pyproject-rpm-macros
  • Remove dependency on setuptools_scm
  • Resolves: rhbz#1877430

python-lxml [4.6.5-1]

  • Update to 4.6.5
  • Security fix for CVE-2021-43818 Resolves: rhbz#2032569

python-more-itertools [8.5.0-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[8.5.0-1]

  • Update to 8.5.0 (#1873653)

[8.4.0-1]

  • Update to 8.4.0
  • Fixes rhbz#1778332

[7.2.0-6]

python-packaging [20.4-4]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[20.4-3]

  • Drop the dependency on six to make the package lighter

[20.4-2]

[20.4-1]

  • Update to 20.4 (#1838285)

[20.3-3]

  • Rebuilt for Python 3.9

[20.3-2]

  • Bootstrap for Python 3.9

[20.3-1]

  • Update to 20.3 (#1810738)

[20.1-2]

[20.1-1]

  • Update to 20.1 (#1794865)

[20.0-2]

  • Ignore broken tests

[20.0-1]

  • Update to 20.0 (#1788012)

python-pluggy [0.13.1-3]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[0.13.1-2]

[0.13.1-1]

  • update to 0.13.1

[0.13.0-4]

  • Rebuilt for Python 3.9

python-ply python-psutil [5.8.0-4]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[5.8.0-3]

  • Disable test_leak_mem test.

[5.8.0-2]

  • Disable test_sensors_temperatures test.

[5.8.0-1]

  • Update to 5.8.0. Fixes rhbz#1909321
  • Re-enable tests (skipping 2 that fail in mock).

[5.7.3-1]

  • Update to 5.7.3 (rhbz#1857187)

[5.7.2-2]

[5.7.2-1]

  • Update to 5.7.2

[5.6.7-3]

  • Add BR on setuptools for all package combinations

[5.6.7-2]

  • Rebuilt for Python 3.9

[5.6.7-1]

  • Update to 5.6.7. Fixes bug 1768362.

python-psycopg2 [2.8.6-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[2.8.6-1]

  • Rebase to upstream version 2.8.6

[2.8.5-3]

[2.8.5-2]

  • Rebuilt for Python 3.9

[2.8.5-1]

  • Rebase to upstream version 2.8.5

python-py [1.10.0-1]

  • Update to 1.10.0.
  • Resolves: rhbz#1877430

[1.9.0-3]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[1.9.0-2]

[1.9.0-1]

  • Update to 1.9.0.

[1.8.2-1]

  • Update to 1.8.2.

[1.8.0-10]

  • Rebuilt for Python 3.9

[1.8.0-9]

  • Bootstrap for Python 3.9

python-pycparser [2.20-3]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[2.20-2]

[2.20-1]

  • Update to 2.20 (#1810349)

python-PyMySQL python-pysocks python-requests [2.25.0-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[2.25.0-1]

  • Update to 2.25.0

[2.24.0-5]

  • Don't BR pytest-cov

[2.24.0-3]

  • Build with pytest 6, older version is no longer required

[2.24.0-2]

[2.24.0-1]

  • Update to 2.24.0
  • Resolves rhbz#1848104

[2.23.0-5]

  • Add requests[security] and requests[socks] subpackages

[2.23.0-4]

  • Test with pytest 4, drop manual requires

[2.23.0-3]

  • Rebuilt for Python 3.9

[2.23.0-2]

  • Bootstrap for Python 3.9

[2.23.0-1]

python-toml [0.10.1-5]

  • Convert spec for python39 module in RHEL8
  • Revert usage of pyproject-rpm-macros
  • Resolves: rhbz#1877430

python-urllib3 [1.25.10-4]

  • Fix for CVE-2021-33503 Catastrophic backtracking in URL authority parser Resolves: rhbz#1968074

python-wcwidth [0.2.5-3]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[0.2.5-2]

[0.2.5-1]

  • Update to 0.2.5 (#1850238)

[0.2.4-1]

  • Update to 0.2.4

[0.2.3-1]

  • Update to 0.2.3

[0.1.9-3]

  • Rebuilt for Python 3.9

[0.1.9-2]

  • Bootstrap for Python 3.9

[0.1.9-1]

  • Update to 0.1.9

python-wheel [1:0.35.1-4]

  • Adjusted the postun scriptlets to enable upgrading to RHEL 9
  • Resolves: rhbz#1933055

PyYAML scipy [1.5.4-3]

  • Specify LDFLAGS explicitly
  • Force preprocessing of Fortran sources to make annobin record proper flags
  • Resolves: rhbz#1778983 rhbz#1877430

[1.5.4-2]

  • Convert from Fedora to the python39 module in RHEL8
  • Resolves: rhbz#1877430

[1.5.4-1]

  • New upstream release 1.5.4
  • Increase test timeout, 300 seconds is not always enough for test_logpdf_overflow on s390x resolves: #1894887

[1.5.3-1]

  • New upstream release 1.5.3 resolves: #1889132

[1.5.2-2]

  • Skip one more test expected to fail on 32-bit architectures

[1.5.2-1]

  • New upstream release 1.5.2 resolves: #1853871 and 1840077

[1.5.0-4]

[1.5.0-3]

[1.5.0-2]

[1.5.0-1]

  • Update to latest version

[1.4.1-2]

  • Rebuilt for Python 3.9

[1.4.1-1]

  • Update to 1.4.1 (bz#1771154)
  • Workaround FTBFS with gcc 10 (bz#1800078)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module python39:3.9 is enabled

python39

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-PyMySQL

0.10.1-2.module+el8.4.0+20109+b7b1db01

python39-cffi

1.14.3-2.module+el8.4.0+20109+b7b1db01

python39-chardet

3.0.4-19.module+el8.4.0+20109+b7b1db01

python39-cryptography

3.3.1-2.module+el8.4.0+20109+b7b1db01

python39-devel

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-idle

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-idna

2.10-3.module+el8.4.0+20109+b7b1db01

python39-libs

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-lxml

4.6.5-1.module+el8.6.0+20625+ee813db2

python39-mod_wsgi

4.7.1-5.module+el8.7.0+20870+babacad2

python39-numpy

1.19.4-3.module+el8.5.0+20364+c7fe1181

python39-numpy-doc

1.19.4-3.module+el8.5.0+20364+c7fe1181

python39-numpy-f2py

1.19.4-3.module+el8.5.0+20364+c7fe1181

python39-pip

20.2.4-7.module+el8.6.0+20625+ee813db2

python39-pip-wheel

20.2.4-7.module+el8.6.0+20625+ee813db2

python39-ply

3.11-10.module+el8.4.0+20109+b7b1db01

python39-psutil

5.8.0-4.module+el8.4.0+20109+b7b1db01

python39-psycopg2

2.8.6-2.module+el8.4.0+20109+b7b1db01

python39-psycopg2-doc

2.8.6-2.module+el8.4.0+20109+b7b1db01

python39-psycopg2-tests

2.8.6-2.module+el8.4.0+20109+b7b1db01

python39-pycparser

2.20-3.module+el8.4.0+20109+b7b1db01

python39-pysocks

1.7.1-4.module+el8.4.0+20109+b7b1db01

python39-pyyaml

5.4.1-1.module+el8.5.0+20364+c7fe1181

python39-requests

2.25.0-2.module+el8.4.0+20109+b7b1db01

python39-rpm-macros

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-scipy

1.5.4-3.module+el8.4.0+20109+b7b1db01

python39-setuptools

50.3.2-4.module+el8.5.0+20364+c7fe1181

python39-setuptools-wheel

50.3.2-4.module+el8.5.0+20364+c7fe1181

python39-six

1.15.0-3.module+el8.4.0+20109+b7b1db01

python39-test

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-tkinter

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-toml

0.10.1-5.module+el8.4.0+20109+b7b1db01

python39-urllib3

1.25.10-4.module+el8.5.0+20364+c7fe1181

python39-wheel

0.35.1-4.module+el8.5.0+20364+c7fe1181

python39-wheel-wheel

0.35.1-4.module+el8.5.0+20364+c7fe1181

Module python39-devel:3.9 is enabled

python39-Cython

0.29.21-5.module+el8.4.0+20109+b7b1db01

python39-attrs

20.3.0-2.module+el8.4.0+20109+b7b1db01

python39-debug

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-iniconfig

1.1.1-2.module+el8.4.0+20109+b7b1db01

python39-more-itertools

8.5.0-2.module+el8.4.0+20109+b7b1db01

python39-packaging

20.4-4.module+el8.4.0+20109+b7b1db01

python39-pluggy

0.13.1-3.module+el8.4.0+20109+b7b1db01

python39-py

1.10.0-1.module+el8.4.0+20109+b7b1db01

python39-pybind11

2.7.1-1.module+el8.6.0+20625+ee813db2

python39-pybind11-devel

2.7.1-1.module+el8.6.0+20625+ee813db2

python39-pyparsing

2.4.7-5.module+el8.4.0+20109+b7b1db01

python39-pytest

6.0.2-2.module+el8.4.0+20109+b7b1db01

python39-wcwidth

0.2.5-3.module+el8.4.0+20109+b7b1db01

Oracle Linux x86_64

Module python39:3.9 is enabled

python39

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-PyMySQL

0.10.1-2.module+el8.4.0+20109+b7b1db01

python39-cffi

1.14.3-2.module+el8.4.0+20109+b7b1db01

python39-chardet

3.0.4-19.module+el8.4.0+20109+b7b1db01

python39-cryptography

3.3.1-2.module+el8.4.0+20109+b7b1db01

python39-devel

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-idle

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-idna

2.10-3.module+el8.4.0+20109+b7b1db01

python39-libs

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-lxml

4.6.5-1.module+el8.6.0+20625+ee813db2

python39-mod_wsgi

4.7.1-5.module+el8.7.0+20870+babacad2

python39-numpy

1.19.4-3.module+el8.5.0+20364+c7fe1181

python39-numpy-doc

1.19.4-3.module+el8.5.0+20364+c7fe1181

python39-numpy-f2py

1.19.4-3.module+el8.5.0+20364+c7fe1181

python39-pip

20.2.4-7.module+el8.6.0+20625+ee813db2

python39-pip-wheel

20.2.4-7.module+el8.6.0+20625+ee813db2

python39-ply

3.11-10.module+el8.4.0+20109+b7b1db01

python39-psutil

5.8.0-4.module+el8.4.0+20109+b7b1db01

python39-psycopg2

2.8.6-2.module+el8.4.0+20109+b7b1db01

python39-psycopg2-doc

2.8.6-2.module+el8.4.0+20109+b7b1db01

python39-psycopg2-tests

2.8.6-2.module+el8.4.0+20109+b7b1db01

python39-pycparser

2.20-3.module+el8.4.0+20109+b7b1db01

python39-pysocks

1.7.1-4.module+el8.4.0+20109+b7b1db01

python39-pyyaml

5.4.1-1.module+el8.5.0+20364+c7fe1181

python39-requests

2.25.0-2.module+el8.4.0+20109+b7b1db01

python39-rpm-macros

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-scipy

1.5.4-3.module+el8.4.0+20109+b7b1db01

python39-setuptools

50.3.2-4.module+el8.5.0+20364+c7fe1181

python39-setuptools-wheel

50.3.2-4.module+el8.5.0+20364+c7fe1181

python39-six

1.15.0-3.module+el8.4.0+20109+b7b1db01

python39-test

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-tkinter

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-toml

0.10.1-5.module+el8.4.0+20109+b7b1db01

python39-urllib3

1.25.10-4.module+el8.5.0+20364+c7fe1181

python39-wheel

0.35.1-4.module+el8.5.0+20364+c7fe1181

python39-wheel-wheel

0.35.1-4.module+el8.5.0+20364+c7fe1181

Module python39-devel:3.9 is enabled

python39-Cython

0.29.21-5.module+el8.4.0+20109+b7b1db01

python39-attrs

20.3.0-2.module+el8.4.0+20109+b7b1db01

python39-debug

3.9.16-1.module+el8.8.0+90007+d415a2d2.2

python39-iniconfig

1.1.1-2.module+el8.4.0+20109+b7b1db01

python39-more-itertools

8.5.0-2.module+el8.4.0+20109+b7b1db01

python39-packaging

20.4-4.module+el8.4.0+20109+b7b1db01

python39-pluggy

0.13.1-3.module+el8.4.0+20109+b7b1db01

python39-py

1.10.0-1.module+el8.4.0+20109+b7b1db01

python39-pybind11

2.7.1-1.module+el8.6.0+20625+ee813db2

python39-pybind11-devel

2.7.1-1.module+el8.6.0+20625+ee813db2

python39-pyparsing

2.4.7-5.module+el8.4.0+20109+b7b1db01

python39-pytest

6.0.2-2.module+el8.4.0+20109+b7b1db01

python39-wcwidth

0.2.5-3.module+el8.4.0+20109+b7b1db01

Связанные CVE

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 8.6
redhat
почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
nvd
почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)

CVSS3: 5.3
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 5.3
debian
почти 2 года назад

An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ...