Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:0418-1

Опубликовано: 16 фев. 2019
Источник: suse-cvrf

Описание

Security update for python-numpy

This update for python-numpy fixes the following issue:

Security issue fixed:

  • CVE-2019-6446: Set allow_pickle to false by default to restrict loading untrusted content (bsc#1122208). With this update we decrease the possibility of allowing remote attackers to execute arbitrary code by misusing numpy.load(). A warning during runtime will show-up when the allow_pickle is not explicitly set.

NOTE: By applying this update the behavior of python-numpy changes, which might break your application. In order to get the old behaviour back, you have to explicitly set allow_pickle to True. Be aware that this should only be done for trusted input, as loading untrusted input might lead to arbitrary code execution.

Список пакетов

Container ses/6/cephcsi/cephcsi:latest
python3-numpy-1.14.0-4.5.1
Container ses/6/rook/ceph:latest
python3-numpy-1.14.0-4.5.1
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server
python3-numpy-1.14.0-4.5.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server
python3-numpy-1.14.0-4.5.1
Image SLES15-SP1-Manager-4-0-GCE-BYOS-Server
python3-numpy-1.14.0-4.5.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-Azure
python3-numpy-1.14.0-4.5.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-EC2-HVM
python3-numpy-1.14.0-4.5.1
Image SLES15-SP2-Manager-4-1-Server-BYOS-GCE
python3-numpy-1.14.0-4.5.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
python3-numpy-1.14.0-4.5.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
python3-numpy-1.14.0-4.5.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
python3-numpy-1.14.0-4.5.1
SUSE Linux Enterprise Module for Basesystem 15
python2-numpy-1.14.0-4.5.1
python2-numpy-devel-1.14.0-4.5.1
python3-numpy-1.14.0-4.5.1
python3-numpy-devel-1.14.0-4.5.1
SUSE Linux Enterprise Module for HPC 15
python2-numpy-gnu-hpc-1.14.0-4.5.1
python2-numpy-gnu-hpc-devel-1.14.0-4.5.1
python2-numpy_1_14_0-gnu-hpc-1.14.0-4.5.1
python2-numpy_1_14_0-gnu-hpc-devel-1.14.0-4.5.1
python3-numpy-gnu-hpc-1.14.0-4.5.1
python3-numpy-gnu-hpc-devel-1.14.0-4.5.1
python3-numpy_1_14_0-gnu-hpc-1.14.0-4.5.1
python3-numpy_1_14_0-gnu-hpc-devel-1.14.0-4.5.1

Описание

** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, as demonstrated by a numpy.load call. NOTE: third parties dispute this issue because it is a behavior that might have legitimate applications in (for example) loading serialized Python object arrays from trusted and authenticated sources.


Затронутые продукты
Container ses/6/cephcsi/cephcsi:latest:python3-numpy-1.14.0-4.5.1
Container ses/6/rook/ceph:latest:python3-numpy-1.14.0-4.5.1
Image SLES15-SP1-Manager-4-0-Azure-BYOS-Server:python3-numpy-1.14.0-4.5.1
Image SLES15-SP1-Manager-4-0-EC2-HVM-BYOS-Server:python3-numpy-1.14.0-4.5.1

Ссылки