Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2021:14198-1

Опубликовано: 05 янв. 2021
Источник: suse-cvrf

Описание

Security update for python

This update for python fixes the following issues:

Security issue fixed:

  • CVE-2019-16056: Fixed a parser issue in the email module. (bsc#1149955)

Список пакетов

SUSE Linux Enterprise Point of Sale 11 SP3
libpython2_6-1_0-2.6.9-40.32.1
python-2.6.9-40.32.2
python-base-2.6.9-40.32.1
python-curses-2.6.9-40.32.2
python-demo-2.6.9-40.32.2
python-doc-2.6-8.40.32.1
python-doc-pdf-2.6-8.40.32.1
python-gdbm-2.6.9-40.32.2
python-idle-2.6.9-40.32.2
python-tk-2.6.9-40.32.2
python-xml-2.6.9-40.32.1
SUSE Linux Enterprise Server 11 SP4-LTSS
libpython2_6-1_0-2.6.9-40.32.1
libpython2_6-1_0-32bit-2.6.9-40.32.1
python-2.6.9-40.32.2
python-32bit-2.6.9-40.32.2
python-base-2.6.9-40.32.1
python-base-32bit-2.6.9-40.32.1
python-curses-2.6.9-40.32.2
python-demo-2.6.9-40.32.2
python-doc-2.6-8.40.32.1
python-doc-pdf-2.6-8.40.32.1
python-gdbm-2.6.9-40.32.2
python-idle-2.6.9-40.32.2
python-tk-2.6.9-40.32.2
python-xml-2.6.9-40.32.1

Описание

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.


Затронутые продукты
SUSE Linux Enterprise Point of Sale 11 SP3:libpython2_6-1_0-2.6.9-40.32.1
SUSE Linux Enterprise Point of Sale 11 SP3:python-2.6.9-40.32.2
SUSE Linux Enterprise Point of Sale 11 SP3:python-base-2.6.9-40.32.1
SUSE Linux Enterprise Point of Sale 11 SP3:python-curses-2.6.9-40.32.2

Ссылки