Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:1580-1

Опубликовано: 18 июн. 2019
Источник: suse-cvrf

Описание

Security update for python

This update for python fixes the following issues:

Security issues fixed:

  • CVE-2019-9948: Fixed a 'file:' blacklist bypass in URIs by using the 'local-file:' scheme instead (bsc#1130847).
  • CVE-2019-9636: Fixed an information disclosure because of incorrect handling of Unicode encoding during NFKC normalization (bsc#1129346).

This update was imported from the SUSE:SLE-12-SP1:Update update project.

Список пакетов

openSUSE Leap 42.3
libpython2_7-1_0-2.7.13-27.15.1
libpython2_7-1_0-32bit-2.7.13-27.15.1
python-2.7.13-27.15.1
python-32bit-2.7.13-27.15.1
python-base-2.7.13-27.15.1
python-base-32bit-2.7.13-27.15.1
python-curses-2.7.13-27.15.1
python-demo-2.7.13-27.15.1
python-devel-2.7.13-27.15.1
python-doc-2.7.13-27.15.1
python-doc-pdf-2.7.13-27.15.1
python-gdbm-2.7.13-27.15.1
python-idle-2.7.13-27.15.1
python-tk-2.7.13-27.15.1
python-xml-2.7.13-27.15.1

Описание

Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, etc. that are cached against a given hostname). The components are: urllib.parse.urlsplit, urllib.parse.urlparse. The attack vector is: A specially crafted URL could be incorrectly parsed to locate cookies or authentication data and send that information to a different host than when parsed correctly.


Затронутые продукты
openSUSE Leap 42.3:libpython2_7-1_0-2.7.13-27.15.1
openSUSE Leap 42.3:libpython2_7-1_0-32bit-2.7.13-27.15.1
openSUSE Leap 42.3:python-2.7.13-27.15.1
openSUSE Leap 42.3:python-32bit-2.7.13-27.15.1

Ссылки

Описание

urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.


Затронутые продукты
openSUSE Leap 42.3:libpython2_7-1_0-2.7.13-27.15.1
openSUSE Leap 42.3:libpython2_7-1_0-32bit-2.7.13-27.15.1
openSUSE Leap 42.3:python-2.7.13-27.15.1
openSUSE Leap 42.3:python-32bit-2.7.13-27.15.1

Ссылки