Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2019:2053-1

Опубликовано: 06 авг. 2019
Источник: suse-cvrf

Описание

Security update for python3

This update for python3 fixes the following issues:

  • CVE-2019-10160: Fixed a regression in urlparse() and urlsplit() introduced by the fix for CVE-2019-9636 (bsc#1138459).
  • CVE-2018-14647: Fixed a denial of service vulnerability caused by a crafted XML document (bsc#1109847).
  • CVE-2018-1000802: Fixed a command injection in the shutil module (bsc#1109663).

Список пакетов

Image SLES12-SP4-Azure-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP4-EC2-HVM-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP4-GCE-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP4-OCI-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP4-SAP-Azure
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-Azure-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-EC2-HVM
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-GCE
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-GCE-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP4-SAP-OCI-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-Azure-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-Azure-Basic-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-Azure-HPC-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-Azure-HPC-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-Azure-SAP-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-Azure-SAP-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-Azure-Standard-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-EC2-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-EC2-ECS-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-EC2-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-EC2-SAP-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-EC2-SAP-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-GCE-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-GCE-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-GCE-SAP-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-GCE-SAP-On-Demand
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-OCI-BYOS-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Enterprise Storage 4
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Enterprise Storage 5
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Desktop 12 SP4
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Module for Web and Scripting 12
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
SUSE Linux Enterprise Server 12 SP1-LTSS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
SUSE Linux Enterprise Server 12 SP2-BCL
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Server 12 SP3-LTSS
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Server 12 SP4
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP1
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE Linux Enterprise Software Development Kit 12 SP4
python3-dbm-3.4.6-25.29.1
python3-devel-3.4.6-25.29.1
SUSE OpenStack Cloud 7
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1
SUSE OpenStack Cloud 8
libpython3_4m1_0-3.4.6-25.29.1
python3-3.4.6-25.29.1
python3-base-3.4.6-25.29.1
python3-curses-3.4.6-25.29.1

Описание

Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:libpython3_4m1_0-3.4.6-25.29.1
Image SLES12-SP4-Azure-BYOS:python3-3.4.6-25.29.1
Image SLES12-SP4-Azure-BYOS:python3-base-3.4.6-25.29.1
Image SLES12-SP4-EC2-HVM-BYOS:libpython3_4m1_0-3.4.6-25.29.1

Ссылки

Описание

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:libpython3_4m1_0-3.4.6-25.29.1
Image SLES12-SP4-Azure-BYOS:python3-3.4.6-25.29.1
Image SLES12-SP4-Azure-BYOS:python3-base-3.4.6-25.29.1
Image SLES12-SP4-EC2-HVM-BYOS:libpython3_4m1_0-3.4.6-25.29.1

Ссылки

Описание

A security regression of CVE-2019-9636 was discovered in python since commit d537ab0ff9767ef024f26246899728f0116b1ec3 affecting versions 2.7, 3.5, 3.6, 3.7 and from v3.8.0a4 through v3.8.0b1, which still allows an attacker to exploit CVE-2019-9636 by abusing the user and password parts of a URL. When an application parses user-supplied URLs to store cookies, authentication credentials, or other kind of information, it is possible for an attacker to provide specially crafted URLs to make the application locate host-related information (e.g. cookies, authentication data) and send them to a different host than where it should, unlike if the URLs had been correctly parsed. The result of an attack may vary based on the application.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:libpython3_4m1_0-3.4.6-25.29.1
Image SLES12-SP4-Azure-BYOS:python3-3.4.6-25.29.1
Image SLES12-SP4-Azure-BYOS:python3-base-3.4.6-25.29.1
Image SLES12-SP4-EC2-HVM-BYOS:libpython3_4m1_0-3.4.6-25.29.1

Ссылки
Уязвимость SUSE-SU-2019:2053-1