Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:3473-1

Опубликовано: 30 сент. 2022
Источник: suse-cvrf

Описание

Security update for python310

This update for python310 fixes the following issues:

Updated to version 3.10.7:

  • CVE-2020-10735: Fixed DoS due to missing limit of amount of digits when converting text to int (bsc#1203125).
  • CVE-2021-28861: Fixed an open redirect in the http server when an URI path starts with // (bsc#1202624).

Список пакетов

Container bci/python:3
libpython3_10-1_0-3.10.7-150400.4.10.1
python310-3.10.7-150400.4.10.1
python310-base-3.10.7-150400.4.10.1
python310-devel-3.10.7-150400.4.10.1
SUSE Linux Enterprise Module for Python 3 15 SP4
libpython3_10-1_0-3.10.7-150400.4.10.1
python310-3.10.7-150400.4.10.1
python310-base-3.10.7-150400.4.10.1
python310-curses-3.10.7-150400.4.10.1
python310-dbm-3.10.7-150400.4.10.1
python310-devel-3.10.7-150400.4.10.1
python310-idle-3.10.7-150400.4.10.1
python310-tk-3.10.7-150400.4.10.1
python310-tools-3.10.7-150400.4.10.1
openSUSE Leap 15.4
libpython3_10-1_0-3.10.7-150400.4.10.1
libpython3_10-1_0-32bit-3.10.7-150400.4.10.1
python310-3.10.7-150400.4.10.1
python310-32bit-3.10.7-150400.4.10.1
python310-base-3.10.7-150400.4.10.1
python310-base-32bit-3.10.7-150400.4.10.1
python310-curses-3.10.7-150400.4.10.1
python310-dbm-3.10.7-150400.4.10.1
python310-devel-3.10.7-150400.4.10.1
python310-doc-3.10.7-150400.4.10.1
python310-doc-devhelp-3.10.7-150400.4.10.1
python310-idle-3.10.7-150400.4.10.1
python310-testsuite-3.10.7-150400.4.10.1
python310-tk-3.10.7-150400.4.10.1
python310-tools-3.10.7-150400.4.10.1

Описание

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.


Затронутые продукты
Container bci/python:3:libpython3_10-1_0-3.10.7-150400.4.10.1
Container bci/python:3:python310-3.10.7-150400.4.10.1
Container bci/python:3:python310-base-3.10.7-150400.4.10.1
Container bci/python:3:python310-devel-3.10.7-150400.4.10.1

Ссылки

Описание

** DISPUTED ** Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."


Затронутые продукты
Container bci/python:3:libpython3_10-1_0-3.10.7-150400.4.10.1
Container bci/python:3:python310-3.10.7-150400.4.10.1
Container bci/python:3:python310-base-3.10.7-150400.4.10.1
Container bci/python:3:python310-devel-3.10.7-150400.4.10.1

Ссылки
Уязвимость SUSE-SU-2022:3473-1