Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:2987

Опубликовано: 07 мая 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: python27:2.7 security update

Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing. The python27 packages provide a stable release of Python 2.7 with a number of additional utilities and database connectors for MySQL and PostgreSQL.

Security Fix(es):

  • pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py (CVE-2022-40897)

  • python: use after free in heappushpop() of heapq module (CVE-2022-48560)

  • python: XML External Entity in XML processing plistlib module (CVE-2022-48565)

  • python-urllib3: Cookie request header isn't stripped during cross-origin redirects (CVE-2023-43804)

  • jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.10 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
babelnoarch10.module+el8.9.0+1531+a18208f5babel-2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm
babelnoarch10.module+el8.9.0+1531+a18208f5babel-2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm
python2x86_6417.module+el8.10.0+1813+4b021305.rocky.0.2python2-2.7.18-17.module+el8.10.0+1813+4b021305.rocky.0.2.x86_64.rpm
python2-attrsnoarch10.module+el8.9.0+1531+a18208f5python2-attrs-17.4.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm
python2-attrsnoarch10.module+el8.9.0+1531+a18208f5python2-attrs-17.4.0-10.module+el8.9.0+1531+a18208f5.noarch.rpm
python2-babelnoarch10.module+el8.9.0+1531+a18208f5python2-babel-2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm
python2-babelnoarch10.module+el8.9.0+1531+a18208f5python2-babel-2.5.1-10.module+el8.9.0+1531+a18208f5.noarch.rpm
python2-backportsx86_6416.module+el8.9.0+1531+a18208f5python2-backports-1.0-16.module+el8.9.0+1531+a18208f5.x86_64.rpm
python2-backports-ssl_match_hostnamenoarch12.module+el8.9.0+1531+a18208f5python2-backports-ssl_match_hostname-3.5.0.1-12.module+el8.9.0+1531+a18208f5.noarch.rpm
python2-backports-ssl_match_hostnamenoarch12.module+el8.9.0+1531+a18208f5python2-backports-ssl_match_hostname-3.5.0.1-12.module+el8.9.0+1531+a18208f5.noarch.rpm

Показывать по

Связанные уязвимости

oracle-oval
больше 1 года назад

ELSA-2024-2987: python27:2.7 security update (MODERATE)

rocky
больше 1 года назад

Moderate: python39:3.9 and python39-devel:3.9 security update

oracle-oval
больше 1 года назад

ELSA-2024-2985: python39:3.9 and python39-devel:3.9 security update (MODERATE)

CVSS3: 5.9
ubuntu
почти 3 года назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.

CVSS3: 5.9
redhat
почти 3 года назад

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.