Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:2344-1

Опубликовано: 08 июл. 2022
Источник: suse-cvrf

Описание

Security update for python

This update for python fixes the following issues:

  • CVE-2015-20107: avoid command injection in the mailcap module (bsc#1198511).

Список пакетов

Image SLES15-SP1-SAPCAL-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP2-SAP-BYOS-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-BYOS-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP3-SAPCAL-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-SAPCAL-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-SAPCAL-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Enterprise Storage 6
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Enterprise Storage 7
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3
python-tk-2.7.18-150000.41.1
SUSE Linux Enterprise Module for Python 2 15 SP3
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP1-BCL
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP1-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP2-BCL
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server for SAP Applications 15
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Manager Proxy 4.1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Manager Retail Branch Server 4.1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Manager Server 4.1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
openSUSE Leap 15.3
libpython2_7-1_0-2.7.18-150000.41.1
libpython2_7-1_0-32bit-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-32bit-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-base-32bit-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-demo-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-doc-2.7.18-150000.41.1
python-doc-pdf-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-idle-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
openSUSE Leap 15.4
libpython2_7-1_0-2.7.18-150000.41.1
libpython2_7-1_0-32bit-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-32bit-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-base-32bit-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-demo-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-doc-2.7.18-150000.41.1
python-doc-pdf-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-idle-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1

Описание

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9


Затронутые продукты
Image SLES15-SP1-SAPCAL-Azure:libpython2_7-1_0-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-Azure:python-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-Azure:python-base-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-Azure:python-xml-2.7.18-150000.41.1

Ссылки
Уязвимость SUSE-SU-2022:2344-1