Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

suse-cvrf Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

SUSE-SU-2024:3297-1

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 18 сСнт. 2024
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: suse-cvrf

ОписаниС

Security update for python-dnspython

This update for python-dnspython fixes the following issue:

  • Fix CVE-2023-29483 (bsc#1230353).

Бписок ΠΏΠ°ΠΊΠ΅Ρ‚ΠΎΠ²

Image SLES12-SP5-Azure-BYOS
python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-HPC-BYOS
python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-HPC-On-Demand
python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-SAP-BYOS
python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-SAP-On-Demand
python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-Standard-On-Demand
python3-dnspython-1.12.0-9.16.2
SUSE Linux Enterprise Module for Public Cloud 12
python-dnspython-1.12.0-9.16.2
python3-dnspython-1.12.0-9.16.2

ОписаниС

eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.


Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΡ€ΠΎΠ΄ΡƒΠΊΡ‚Ρ‹
Image SLES12-SP5-Azure-BYOS:python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-HPC-BYOS:python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-HPC-On-Demand:python3-dnspython-1.12.0-9.16.2
Image SLES12-SP5-Azure-SAP-BYOS:python3-dnspython-1.12.0-9.16.2

Бсылки
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ SUSE-SU-2024:3297-1