Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:2699-1

Опубликовано: 21 сент. 2020
Источник: suse-cvrf

Описание

Security update for python3

This update for python3 fixes the following issues:

  • CVE-2019-20907: Fixed denial of service by avoiding possible infinite loop in specifically crafted tarball (bsc#1174091).
  • CVE-2020-14422: Fixed an improper computation of hash values in the IPv4Interface and IPv6Interface could have led to denial of service (bsc#1173274).
  • CVE-2019-16935: Fixed a reflected XSS in python/Lib/DocXMLRPCServer.py (bsc#1153238).
  • CVE-2019-9947: Fixed an issue in urllib2 which allowed CRLF injection if the attacker controls a url parameter (bsc#1130840).
  • If the locale is 'C', coerce it to C.UTF-8 (bsc#1162423).

Список пакетов

HPE Helion OpenStack 8
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
Image SLES12-SP4-Azure-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP4-EC2-HVM-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP4-GCE-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP4-OCI-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP4-SAP-Azure
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-Azure-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-EC2-HVM
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-GCE
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-GCE-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP4-SAP-OCI-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-Azure-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-Azure-Basic-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-Azure-HPC-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-Azure-HPC-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-Azure-SAP-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-Azure-SAP-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-Azure-Standard-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-EC2-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-EC2-ECS-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-EC2-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-EC2-SAP-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-EC2-SAP-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-GCE-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-GCE-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-GCE-SAP-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-GCE-SAP-On-Demand
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-OCI-BYOS-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
Image SLES12-SP5-OCI-BYOS-SAP-BYOS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
SUSE Enterprise Storage 5
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE Linux Enterprise Module for Web and Scripting 12
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
SUSE Linux Enterprise Server 12 SP2-BCL
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
SUSE Linux Enterprise Server 12 SP2-LTSS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE Linux Enterprise Server 12 SP3-BCL
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
SUSE Linux Enterprise Server 12 SP3-LTSS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE Linux Enterprise Server 12 SP4-LTSS
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE Linux Enterprise Server 12 SP5
libpython3_4m1_0-3.4.10-25.52.1
libpython3_4m1_0-32bit-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
python3-tk-3.4.10-25.52.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libpython3_4m1_0-3.4.10-25.52.1
libpython3_4m1_0-32bit-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
python3-tk-3.4.10-25.52.1
SUSE Linux Enterprise Software Development Kit 12 SP5
python3-dbm-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE OpenStack Cloud 7
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE OpenStack Cloud 8
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE OpenStack Cloud 9
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE OpenStack Cloud Crowbar 8
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1
SUSE OpenStack Cloud Crowbar 9
libpython3_4m1_0-3.4.10-25.52.1
python3-3.4.10-25.52.1
python3-base-3.4.10-25.52.1
python3-curses-3.4.10-25.52.1
python3-devel-3.4.10-25.52.1

Описание

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.


Затронутые продукты
HPE Helion OpenStack 8:libpython3_4m1_0-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-base-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-curses-3.4.10-25.52.1

Ссылки

Описание

http.cookiejar.DefaultPolicy.domain_return_ok in Lib/http/cookiejar.py in Python before 3.7.3 does not correctly validate the domain: it can be tricked into sending existing cookies to the wrong server. An attacker may abuse this flaw by using a server with a hostname that has another valid hostname as a suffix (e.g., pythonicexample.com to steal cookies for example.com). When a program uses http.cookiejar.DefaultPolicy and tries to do an HTTP connection to an attacker-controlled server, existing cookies can be leaked to the attacker. This affects 2.x through 2.7.16, 3.x before 3.4.10, 3.5.x before 3.5.7, 3.6.x before 3.6.9, and 3.7.x before 3.7.3.


Затронутые продукты
HPE Helion OpenStack 8:libpython3_4m1_0-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-base-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-curses-3.4.10-25.52.1

Ссылки

Описание

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.


Затронутые продукты
HPE Helion OpenStack 8:libpython3_4m1_0-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-base-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-curses-3.4.10-25.52.1

Ссылки

Описание

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.


Затронутые продукты
HPE Helion OpenStack 8:libpython3_4m1_0-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-base-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-curses-3.4.10-25.52.1

Ссылки

Описание

In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.


Затронутые продукты
HPE Helion OpenStack 8:libpython3_4m1_0-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-base-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-curses-3.4.10-25.52.1

Ссылки

Описание

An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the first argument to urllib.request.urlopen with \r\n (specifically in the path component of a URL that lacks a ? character) followed by an HTTP header or a Redis command. This is similar to the CVE-2019-9740 query string issue. This is fixed in: v2.7.17, v2.7.17rc1, v2.7.18, v2.7.18rc1; v3.5.10, v3.5.10rc1, v3.5.8, v3.5.8rc1, v3.5.8rc2, v3.5.9; v3.6.10, v3.6.10rc1, v3.6.11, v3.6.11rc1, v3.6.12, v3.6.9, v3.6.9rc1; v3.7.4, v3.7.4rc1, v3.7.4rc2, v3.7.5, v3.7.5rc1, v3.7.6, v3.7.6rc1, v3.7.7, v3.7.7rc1, v3.7.8, v3.7.8rc1, v3.7.9.


Затронутые продукты
HPE Helion OpenStack 8:libpython3_4m1_0-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-base-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-curses-3.4.10-25.52.1

Ссылки

Описание

Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entries to be created. This is fixed in: v3.5.10, v3.5.10rc1; v3.6.12; v3.7.9; v3.8.4, v3.8.4rc1, v3.8.5, v3.8.6, v3.8.6rc1; v3.9.0, v3.9.0b4, v3.9.0b5, v3.9.0rc1, v3.9.0rc2.


Затронутые продукты
HPE Helion OpenStack 8:libpython3_4m1_0-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-base-3.4.10-25.52.1
HPE Helion OpenStack 8:python3-curses-3.4.10-25.52.1

Ссылки
Уязвимость SUSE-SU-2020:2699-1