Описание
Security update for python
This update for python fixes the following issues:
- CVE-2015-20107: avoid command injection in the mailcap module (bsc#1198511).
Список пакетов
Image SLES15-SP1-SAPCAL-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP2-SAP-BYOS-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-BYOS-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP2-SAP-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-Manager-4-2-Server-BYOS-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
libpython2_7-1_0-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
Image SLES15-SP3-SAPCAL-Azure
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-SAPCAL-EC2-HVM
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Image SLES15-SP3-SAPCAL-GCE
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Enterprise Storage 6
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Enterprise Storage 7
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP3
python-tk-2.7.18-150000.41.1
SUSE Linux Enterprise Module for Python 2 15 SP3
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP1-BCL
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP1-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP2-BCL
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server 15-LTSS
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server for SAP Applications 15
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Manager Proxy 4.1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Manager Retail Branch Server 4.1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
SUSE Manager Server 4.1
libpython2_7-1_0-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
openSUSE Leap 15.3
libpython2_7-1_0-2.7.18-150000.41.1
libpython2_7-1_0-32bit-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-32bit-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-base-32bit-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-demo-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-doc-2.7.18-150000.41.1
python-doc-pdf-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-idle-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
openSUSE Leap 15.4
libpython2_7-1_0-2.7.18-150000.41.1
libpython2_7-1_0-32bit-2.7.18-150000.41.1
python-2.7.18-150000.41.1
python-32bit-2.7.18-150000.41.1
python-base-2.7.18-150000.41.1
python-base-32bit-2.7.18-150000.41.1
python-curses-2.7.18-150000.41.1
python-demo-2.7.18-150000.41.1
python-devel-2.7.18-150000.41.1
python-doc-2.7.18-150000.41.1
python-doc-pdf-2.7.18-150000.41.1
python-gdbm-2.7.18-150000.41.1
python-idle-2.7.18-150000.41.1
python-tk-2.7.18-150000.41.1
python-xml-2.7.18-150000.41.1
Ссылки
- Link for SUSE-SU-2022:2344-1
- E-Mail link for SUSE-SU-2022:2344-1
- SUSE Security Ratings
- SUSE Bug 1198511
- SUSE CVE CVE-2015-20107 page
Описание
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Затронутые продукты
Image SLES15-SP1-SAPCAL-Azure:libpython2_7-1_0-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-Azure:python-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-Azure:python-base-2.7.18-150000.41.1
Image SLES15-SP1-SAPCAL-Azure:python-xml-2.7.18-150000.41.1
Ссылки
- CVE-2015-20107
- SUSE Bug 1198511
- SUSE Bug 1200507
- SUSE Bug 1201777
- SUSE Bug 1201791
- SUSE Bug 1205068
- SUSE Bug 1208337