Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:2351-1

Опубликовано: 11 июл. 2022
Источник: suse-cvrf

Описание

Security update for python3

This update for python3 fixes the following issues:

Security issues fixed:

  • CVE-2021-3572: Update bundled pip wheel to the latest SLE version (bsc#1186819)
  • CVE-2015-20107: avoid command injection in the mailcap module (bsc#1198511).

Other bugs fixed:

  • Remove shebangs from from python-base libraries in _libdir (bsc#1193179, bsc#1192249).

Список пакетов

Image SLES15-SP1-CHOST-BYOS-Azure
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-EC2
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-GCE
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP1-SAPCAL-Azure
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP1-SAPCAL-EC2-HVM
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP1-SAPCAL-GCE
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-BYOS-Azure
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-BYOS-EC2-HVM
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-BYOS-GCE
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-CHOST-BYOS-Aliyun
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
Image SLES15-SP2-CHOST-BYOS-Azure
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
Image SLES15-SP2-CHOST-BYOS-EC2
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
Image SLES15-SP2-CHOST-BYOS-GCE
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
Image SLES15-SP2-HPC-BYOS-Azure
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-HPC-BYOS-EC2-HVM
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-Azure
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-BYOS-Azure
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-BYOS-GCE
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-EC2-HVM
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
Image SLES15-SP2-SAP-GCE
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
SUSE Enterprise Storage 6
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-testsuite-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Enterprise Storage 7
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise High Performance Computing 15 SP1-ESPOS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-testsuite-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-testsuite-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise High Performance Computing 15 SP2-ESPOS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise High Performance Computing 15-LTSS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Micro 5.1
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server 15 SP1-BCL
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-testsuite-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server 15 SP1-LTSS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-testsuite-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server 15 SP2-BCL
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server 15 SP2-LTSS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server 15-LTSS
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server for SAP Applications 15
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-testsuite-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Manager Proxy 4.1
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Manager Retail Branch Server 4.1
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1
SUSE Manager Server 4.1
libpython3_6m1_0-3.6.15-150000.3.106.1
python3-3.6.15-150000.3.106.1
python3-base-3.6.15-150000.3.106.1
python3-curses-3.6.15-150000.3.106.1
python3-dbm-3.6.15-150000.3.106.1
python3-devel-3.6.15-150000.3.106.1
python3-idle-3.6.15-150000.3.106.1
python3-tk-3.6.15-150000.3.106.1
python3-tools-3.6.15-150000.3.106.1

Описание

In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9


Затронутые продукты
Image SLES15-SP1-CHOST-BYOS-Azure:libpython3_6m1_0-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-Azure:python3-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-Azure:python3-base-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-EC2:libpython3_6m1_0-3.6.15-150000.3.106.1

Ссылки

Описание

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.


Затронутые продукты
Image SLES15-SP1-CHOST-BYOS-Azure:libpython3_6m1_0-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-Azure:python3-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-Azure:python3-base-3.6.15-150000.3.106.1
Image SLES15-SP1-CHOST-BYOS-EC2:libpython3_6m1_0-3.6.15-150000.3.106.1

Ссылки
Уязвимость SUSE-SU-2022:2351-1