Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19589

Опубликовано: 29 июн. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-19589: python security update (IMPORTANT)

[2.7.5-94.0.9]

  • Fix for CVE-2026-4786 [Orabug: 39418723]

[2.7.5-94.0.7]

  • Fix for CVE-2026-4519 [Orabug: 39243798]

[2.7.5-94.0.5]

  • Fix for CVE-2025-15366 and CVE-2025-15367 [Orabug: 39114639]

[2.7.5-94.0.3]

  • Fix for CVE-2025-12084 [Orabug: 38902314]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

python

2.7.5-94.0.9.el7_9

python-debug

2.7.5-94.0.9.el7_9

python-devel

2.7.5-94.0.9.el7_9

python-libs

2.7.5-94.0.9.el7_9

python-test

2.7.5-94.0.9.el7_9

python-tools

2.7.5-94.0.9.el7_9

tkinter

2.7.5-94.0.9.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
redhat
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
nvd
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

msrc
3 месяца назад

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

CVSS3: 7.1
debian
4 месяца назад

Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...