Описание
ELSA-2023-5998: python39:3.9 and python39-devel:3.9 security update (IMPORTANT)
Cython [0.29.21-5]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
mod_wsgi [4.7.1-5]
- Core dumped upon file upload >= 1GB Resolves: rhbz#2125172
numpy [1.19.4-3]
- Adjusted the postun scriptlets to enable upgrading to RHEL 9
- Resolves: rhbz#1933055
pybind11 [2.7.1-1]
- Update to 2.7.1
- Resolves: rhbz#2000212
pytest [6.0.2-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[6.0.2-1]
- Update to 6.0.2.
[6.0.1-1]
- Update to 6.0.1 (#1862097)
[6.0.0~rc1-1]
- Update to 6.0.0rc1
[5.4.3-2]
[5.4.3-1]
- Update to 5.4.3.
[5.4.2-1]
- Update to 5.4.2 (#1707986)
[4.6.10-3]
- Rebuilt for Python 3.9
[4.6.10-2]
- Bootstrap for Python 3.9
[4.6.10-1]
- Update to 4.6.10.
[4.6.9-2]
[4.6.9-1]
- Update to 4.6.9.
[4.6.8-1]
- Update to 4.6.8.
[4.6.7-1]
- Update to 4.6.7
python39 python3x-pip [20.2.4-7]
- Remove bundled windows executables
- Resolves: rhbz#2006790
python3x-setuptools [50.3.2-4]
- Adjusted the postun scriptlets to enable upgrading to RHEL 9
- Resolves: rhbz#1933055
python3x-six [1.15.0-3]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[1.15.0-2]
[1.15.0-1]
- Update to 1.15.0 (#1838702)
[1.14.0-4]
- Rebuilt for Python 3.9
[1.14.0-3]
- Bootstrap for Python 3.9
[1.14.0-2]
[1.14.0-1]
- Update to 1.14.0 (#1768982) for Python 3.9 support (#1788494)
- Drop old obsoletes for platform-python-six
python-attrs [20.3.0-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[20.3.0-1]
- Update to 20.3.0 (#1894866)
[20.2.0-1]
- Update to 20.2.0 (#1876063)
[20.1.0-1]
- Update to 20.1.0 (#1870794)
[19.3.0-5]
[19.3.0-4]
- Rebuilt for Python 3.9
python-cffi [1.14.3-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[1.14.3-1]
- Update to 1.14.3
[1.14.2-1]
- Update to 1.14.2 (#1869032)
[1.14.1-1]
- Update to 1.14.1
- Fixes: rhbz#1860698
- Fixes: rhbz#1865276
[1.14.0-2]
- Rebuilt for Python 3.9
[1.14.0]
- Update to 1.14.0 (#1800646)
python-chardet python-cryptography [3.3.1-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[3.3.1-1]
- Update to 3.3.1 (#1905756)
[3.2.1-1]
- Update to 3.2.1 (#1892153)
[3.2-1]
- Update to 3.2 (#1891378)
[3.1-1]
- Update to 3.1 (#1872978)
[3.0-2]
[3.0-1]
- Update to 3.0 (#185897)
[2.9-3]
- Rebuilt for Python 3.9
[2.9-2]
- add source file verification
[2.9-1]
- Update to 2.9 (#1820348)
python-idna [2.10-3]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[2.10-2]
[2.10-1]
- Update to 2.10 (#1851653)
[2.9-2]
- Rebuilt for Python 3.9
[2.9-1]
- Update to 2.9 (#1803654)
python-iniconfig [1.1.1-2]
- Convert from Fedora to the python39 module in RHEL8
- Revert usage of pyproject-rpm-macros
- Remove dependency on setuptools_scm
- Resolves: rhbz#1877430
python-lxml [4.6.5-1]
- Update to 4.6.5
- Security fix for CVE-2021-43818 Resolves: rhbz#2032569
python-more-itertools [8.5.0-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[8.5.0-1]
- Update to 8.5.0 (#1873653)
[8.4.0-1]
- Update to 8.4.0
- Fixes rhbz#1778332
[7.2.0-6]
python-packaging [20.4-4]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[20.4-3]
- Drop the dependency on six to make the package lighter
[20.4-2]
[20.4-1]
- Update to 20.4 (#1838285)
[20.3-3]
- Rebuilt for Python 3.9
[20.3-2]
- Bootstrap for Python 3.9
[20.3-1]
- Update to 20.3 (#1810738)
[20.1-2]
[20.1-1]
- Update to 20.1 (#1794865)
[20.0-2]
- Ignore broken tests
[20.0-1]
- Update to 20.0 (#1788012)
python-pluggy [0.13.1-3]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[0.13.1-2]
[0.13.1-1]
- update to 0.13.1
[0.13.0-4]
- Rebuilt for Python 3.9
python-ply python-psutil [5.8.0-4]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[5.8.0-3]
- Disable test_leak_mem test.
[5.8.0-2]
- Disable test_sensors_temperatures test.
[5.8.0-1]
- Update to 5.8.0. Fixes rhbz#1909321
- Re-enable tests (skipping 2 that fail in mock).
[5.7.3-1]
- Update to 5.7.3 (rhbz#1857187)
[5.7.2-2]
[5.7.2-1]
- Update to 5.7.2
[5.6.7-3]
- Add BR on setuptools for all package combinations
[5.6.7-2]
- Rebuilt for Python 3.9
[5.6.7-1]
- Update to 5.6.7. Fixes bug 1768362.
python-psycopg2 [2.8.6-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[2.8.6-1]
- Rebase to upstream version 2.8.6
[2.8.5-3]
[2.8.5-2]
- Rebuilt for Python 3.9
[2.8.5-1]
- Rebase to upstream version 2.8.5
python-py [1.10.0-1]
- Update to 1.10.0.
- Resolves: rhbz#1877430
[1.9.0-3]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[1.9.0-2]
[1.9.0-1]
- Update to 1.9.0.
[1.8.2-1]
- Update to 1.8.2.
[1.8.0-10]
- Rebuilt for Python 3.9
[1.8.0-9]
- Bootstrap for Python 3.9
python-pycparser [2.20-3]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[2.20-2]
[2.20-1]
- Update to 2.20 (#1810349)
python-PyMySQL python-pysocks python-requests [2.25.0-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[2.25.0-1]
- Update to 2.25.0
[2.24.0-5]
- Don't BR pytest-cov
[2.24.0-3]
- Build with pytest 6, older version is no longer required
[2.24.0-2]
[2.24.0-1]
- Update to 2.24.0
- Resolves rhbz#1848104
[2.23.0-5]
- Add requests[security] and requests[socks] subpackages
[2.23.0-4]
- Test with pytest 4, drop manual requires
[2.23.0-3]
- Rebuilt for Python 3.9
[2.23.0-2]
- Bootstrap for Python 3.9
[2.23.0-1]
- Update to 2.23.0 (#1804863).
- https://requests.readthedocs.io/en/latest/community/updates/
python-toml [0.10.1-5]
- Convert spec for python39 module in RHEL8
- Revert usage of pyproject-rpm-macros
- Resolves: rhbz#1877430
python-urllib3 [1.25.10-4]
- Fix for CVE-2021-33503 Catastrophic backtracking in URL authority parser Resolves: rhbz#1968074
python-wcwidth [0.2.5-3]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[0.2.5-2]
[0.2.5-1]
- Update to 0.2.5 (#1850238)
[0.2.4-1]
- Update to 0.2.4
[0.2.3-1]
- Update to 0.2.3
[0.1.9-3]
- Rebuilt for Python 3.9
[0.1.9-2]
- Bootstrap for Python 3.9
[0.1.9-1]
- Update to 0.1.9
python-wheel [1:0.35.1-4]
- Adjusted the postun scriptlets to enable upgrading to RHEL 9
- Resolves: rhbz#1933055
PyYAML scipy [1.5.4-3]
- Specify LDFLAGS explicitly
- Force preprocessing of Fortran sources to make annobin record proper flags
- Resolves: rhbz#1778983 rhbz#1877430
[1.5.4-2]
- Convert from Fedora to the python39 module in RHEL8
- Resolves: rhbz#1877430
[1.5.4-1]
- New upstream release 1.5.4
- Increase test timeout, 300 seconds is not always enough for test_logpdf_overflow on s390x resolves: #1894887
[1.5.3-1]
- New upstream release 1.5.3 resolves: #1889132
[1.5.2-2]
- Skip one more test expected to fail on 32-bit architectures
[1.5.2-1]
- New upstream release 1.5.2 resolves: #1853871 and 1840077
[1.5.0-4]
[1.5.0-3]
- Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
[1.5.0-2]
[1.5.0-1]
- Update to latest version
[1.4.1-2]
- Rebuilt for Python 3.9
[1.4.1-1]
- Update to 1.4.1 (bz#1771154)
- Workaround FTBFS with gcc 10 (bz#1800078)
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
Module python39:3.9 is enabled
python39
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-PyMySQL
0.10.1-2.module+el8.4.0+20109+b7b1db01
python39-cffi
1.14.3-2.module+el8.4.0+20109+b7b1db01
python39-chardet
3.0.4-19.module+el8.4.0+20109+b7b1db01
python39-cryptography
3.3.1-2.module+el8.4.0+20109+b7b1db01
python39-devel
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-idle
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-idna
2.10-3.module+el8.4.0+20109+b7b1db01
python39-libs
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-lxml
4.6.5-1.module+el8.6.0+20625+ee813db2
python39-mod_wsgi
4.7.1-5.module+el8.7.0+20870+babacad2
python39-numpy
1.19.4-3.module+el8.5.0+20364+c7fe1181
python39-numpy-doc
1.19.4-3.module+el8.5.0+20364+c7fe1181
python39-numpy-f2py
1.19.4-3.module+el8.5.0+20364+c7fe1181
python39-pip
20.2.4-7.module+el8.6.0+20625+ee813db2
python39-pip-wheel
20.2.4-7.module+el8.6.0+20625+ee813db2
python39-ply
3.11-10.module+el8.4.0+20109+b7b1db01
python39-psutil
5.8.0-4.module+el8.4.0+20109+b7b1db01
python39-psycopg2
2.8.6-2.module+el8.4.0+20109+b7b1db01
python39-psycopg2-doc
2.8.6-2.module+el8.4.0+20109+b7b1db01
python39-psycopg2-tests
2.8.6-2.module+el8.4.0+20109+b7b1db01
python39-pycparser
2.20-3.module+el8.4.0+20109+b7b1db01
python39-pysocks
1.7.1-4.module+el8.4.0+20109+b7b1db01
python39-pyyaml
5.4.1-1.module+el8.5.0+20364+c7fe1181
python39-requests
2.25.0-2.module+el8.4.0+20109+b7b1db01
python39-rpm-macros
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-scipy
1.5.4-3.module+el8.4.0+20109+b7b1db01
python39-setuptools
50.3.2-4.module+el8.5.0+20364+c7fe1181
python39-setuptools-wheel
50.3.2-4.module+el8.5.0+20364+c7fe1181
python39-six
1.15.0-3.module+el8.4.0+20109+b7b1db01
python39-test
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-tkinter
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-toml
0.10.1-5.module+el8.4.0+20109+b7b1db01
python39-urllib3
1.25.10-4.module+el8.5.0+20364+c7fe1181
python39-wheel
0.35.1-4.module+el8.5.0+20364+c7fe1181
python39-wheel-wheel
0.35.1-4.module+el8.5.0+20364+c7fe1181
Module python39-devel:3.9 is enabled
python39-Cython
0.29.21-5.module+el8.4.0+20109+b7b1db01
python39-attrs
20.3.0-2.module+el8.4.0+20109+b7b1db01
python39-debug
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-iniconfig
1.1.1-2.module+el8.4.0+20109+b7b1db01
python39-more-itertools
8.5.0-2.module+el8.4.0+20109+b7b1db01
python39-packaging
20.4-4.module+el8.4.0+20109+b7b1db01
python39-pluggy
0.13.1-3.module+el8.4.0+20109+b7b1db01
python39-py
1.10.0-1.module+el8.4.0+20109+b7b1db01
python39-pybind11
2.7.1-1.module+el8.6.0+20625+ee813db2
python39-pybind11-devel
2.7.1-1.module+el8.6.0+20625+ee813db2
python39-pyparsing
2.4.7-5.module+el8.4.0+20109+b7b1db01
python39-pytest
6.0.2-2.module+el8.4.0+20109+b7b1db01
python39-wcwidth
0.2.5-3.module+el8.4.0+20109+b7b1db01
Oracle Linux x86_64
Module python39:3.9 is enabled
python39
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-PyMySQL
0.10.1-2.module+el8.4.0+20109+b7b1db01
python39-cffi
1.14.3-2.module+el8.4.0+20109+b7b1db01
python39-chardet
3.0.4-19.module+el8.4.0+20109+b7b1db01
python39-cryptography
3.3.1-2.module+el8.4.0+20109+b7b1db01
python39-devel
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-idle
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-idna
2.10-3.module+el8.4.0+20109+b7b1db01
python39-libs
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-lxml
4.6.5-1.module+el8.6.0+20625+ee813db2
python39-mod_wsgi
4.7.1-5.module+el8.7.0+20870+babacad2
python39-numpy
1.19.4-3.module+el8.5.0+20364+c7fe1181
python39-numpy-doc
1.19.4-3.module+el8.5.0+20364+c7fe1181
python39-numpy-f2py
1.19.4-3.module+el8.5.0+20364+c7fe1181
python39-pip
20.2.4-7.module+el8.6.0+20625+ee813db2
python39-pip-wheel
20.2.4-7.module+el8.6.0+20625+ee813db2
python39-ply
3.11-10.module+el8.4.0+20109+b7b1db01
python39-psutil
5.8.0-4.module+el8.4.0+20109+b7b1db01
python39-psycopg2
2.8.6-2.module+el8.4.0+20109+b7b1db01
python39-psycopg2-doc
2.8.6-2.module+el8.4.0+20109+b7b1db01
python39-psycopg2-tests
2.8.6-2.module+el8.4.0+20109+b7b1db01
python39-pycparser
2.20-3.module+el8.4.0+20109+b7b1db01
python39-pysocks
1.7.1-4.module+el8.4.0+20109+b7b1db01
python39-pyyaml
5.4.1-1.module+el8.5.0+20364+c7fe1181
python39-requests
2.25.0-2.module+el8.4.0+20109+b7b1db01
python39-rpm-macros
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-scipy
1.5.4-3.module+el8.4.0+20109+b7b1db01
python39-setuptools
50.3.2-4.module+el8.5.0+20364+c7fe1181
python39-setuptools-wheel
50.3.2-4.module+el8.5.0+20364+c7fe1181
python39-six
1.15.0-3.module+el8.4.0+20109+b7b1db01
python39-test
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-tkinter
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-toml
0.10.1-5.module+el8.4.0+20109+b7b1db01
python39-urllib3
1.25.10-4.module+el8.5.0+20364+c7fe1181
python39-wheel
0.35.1-4.module+el8.5.0+20364+c7fe1181
python39-wheel-wheel
0.35.1-4.module+el8.5.0+20364+c7fe1181
Module python39-devel:3.9 is enabled
python39-Cython
0.29.21-5.module+el8.4.0+20109+b7b1db01
python39-attrs
20.3.0-2.module+el8.4.0+20109+b7b1db01
python39-debug
3.9.16-1.module+el8.8.0+90007+d415a2d2.2
python39-iniconfig
1.1.1-2.module+el8.4.0+20109+b7b1db01
python39-more-itertools
8.5.0-2.module+el8.4.0+20109+b7b1db01
python39-packaging
20.4-4.module+el8.4.0+20109+b7b1db01
python39-pluggy
0.13.1-3.module+el8.4.0+20109+b7b1db01
python39-py
1.10.0-1.module+el8.4.0+20109+b7b1db01
python39-pybind11
2.7.1-1.module+el8.6.0+20625+ee813db2
python39-pybind11-devel
2.7.1-1.module+el8.6.0+20625+ee813db2
python39-pyparsing
2.4.7-5.module+el8.4.0+20109+b7b1db01
python39-pytest
6.0.2-2.module+el8.4.0+20109+b7b1db01
python39-wcwidth
0.2.5-3.module+el8.4.0+20109+b7b1db01
Связанные CVE
Связанные уязвимости
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authentication. If a TLS server-side socket is created, receives data into the socket buffer, and then is closed quickly, there is a brief window where the SSLSocket instance will detect the socket as "not connected" and won't initiate a handshake, but buffered data will still be readable from the socket buffer. This data will not be authenticated if the server-side TLS peer is expecting client certificate authentication, and is indistinguishable from valid TLS stream data. Data is limited in size to the amount that will fit in the buffer. (The TLS connection cannot directly be used for data exfiltration because the vulnerable code path requires that the connection be closed on initialization of the SSLSocket.)
An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, ...