Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2024:8834

Опубликовано: 29 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: python-gevent security update

gevent is a coroutine-based Python networking library that uses greenlet to provide a high-level synchronous API on top of libevent event loop. Features include: * convenient API around greenlets * familiar synchronization primitives (gevent.event, gevent.queue) * socket module that cooperates * WSGI server on top of libevent-http * DNS requests done through libevent-dns * monkey patching utility to get pure Python modules to cooperate

Security Fix(es):

  • python-gevent: privilege escalation via a crafted script to the WSGIServer component (CVE-2023-41419)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
python3-geventaarch645.el8python3-gevent-1.2.2-5.el8.aarch64.rpm
python3-geventx86_645.el8python3-gevent-1.2.2-5.el8.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 3 года назад

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

CVSS3: 9.1
redhat
почти 3 года назад

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

CVSS3: 9.8
nvd
почти 3 года назад

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

CVSS3: 9.8
msrc
почти 3 года назад

An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

CVSS3: 9.8
debian
почти 3 года назад

An issue in Gevent before version 23.9.0 allows a remote attacker to e ...