Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-1750

Опубликовано: 13 мар. 2025
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2025-1750: python3 security update (MODERATE)

[3.6.8-21.0.3]

  • Fix DoS parsing crafted tarfile headers [Orabug: 37626372][CVE-2024-6232]
  • Disable test_socket in the PGO profile task.

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

python3

3.6.8-21.0.3.el7_9

python3-debug

3.6.8-21.0.3.el7_9

python3-devel

3.6.8-21.0.3.el7_9

python3-idle

3.6.8-21.0.3.el7_9

python3-libs

3.6.8-21.0.3.el7_9

python3-test

3.6.8-21.0.3.el7_9

python3-tkinter

3.6.8-21.0.3.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

CVSS3: 7.5
redhat
10 месяцев назад

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

CVSS3: 7.5
nvd
10 месяцев назад

There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

CVSS3: 7.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
10 месяцев назад

There is a MEDIUM severity vulnerability affecting CPython. Regul ...