Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-35838

Опубликовано: 21 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2026-35838: python3 security update (IMPORTANT)

[3.6.8-21.0.13]

  • Security update CVE-2026-4786 [Orabug: 39695277]

[3.6.8-21.0.11]

  • Security update CVE-2026-4519 [Orabug: 39246828]

[3.6.8-21.0.9]

  • Security update CVE-2025-15366, CVE-2025-15367, CVE-2026-1299 [Orabug: 39159999]

[3.6.8-21.0.7]

  • Security update CVE-2025-12084 [Orabug: 38971895]

[3.6.8-21.0.5]

  • tarfile now validates archives to ensure member offsets are non-negative [Orabug: 38442771][CVE-2025-8194]

[3.6.8-21.0.3]

  • Fix DoS parsing crafted tarfile headers [Orabug: 37626372][CVE-2024-6232]
  • Disable test_socket in the PGO profile task.

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

python3

3.6.8-21.0.13.el7_9

python3-debug

3.6.8-21.0.13.el7_9

python3-devel

3.6.8-21.0.13.el7_9

python3-idle

3.6.8-21.0.13.el7_9

python3-libs

3.6.8-21.0.13.el7_9

python3-test

3.6.8-21.0.13.el7_9

python3-tkinter

3.6.8-21.0.13.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.1
ubuntu
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
redhat
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

CVSS3: 7.1
nvd
4 месяца назад

Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.

msrc
3 месяца назад

Incomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()

CVSS3: 7.1
debian
4 месяца назад

Mitgation ofCVE-2026-4519 was incomplete. If the URL contained "%actio ...