Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2453-1

Опубликовано: 09 нояб. 2019
Источник: suse-cvrf

Описание

Security update for python3

This update for python3 to 3.6.9 fixes the following issues:

Security issues fixed:

  • CVE-2019-16056: Fixed a parser issue in the email module. (bsc#1149955)
  • CVE-2019-16935: Fixed a reflected XSS in python/Lib/DocXMLRPCServer.py (bsc#1153238).

Non-security issues fixed:

  • Fixed regression of OpenSSL 1.1.1b-1 in EVP_PBE_scrypt() with salt=NULL. (bsc#1151490)
  • Improved locale handling by implementing PEP 538.

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libpython3_6m1_0-3.6.9-lp150.2.14.1
libpython3_6m1_0-32bit-3.6.9-lp150.2.14.1
python3-3.6.9-lp150.2.14.1
python3-32bit-3.6.9-lp150.2.14.1
python3-base-3.6.9-lp150.2.14.1
python3-base-32bit-3.6.9-lp150.2.14.1
python3-curses-3.6.9-lp150.2.14.1
python3-dbm-3.6.9-lp150.2.14.1
python3-devel-3.6.9-lp150.2.14.1
python3-idle-3.6.9-lp150.2.14.1
python3-testsuite-3.6.9-lp150.2.14.1
python3-tk-3.6.9-lp150.2.14.1
python3-tools-3.6.9-lp150.2.14.1

Описание

An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address that should be denied. An attack may be the same as in CVE-2019-11340; however, this CVE applies to Python more generally.


Затронутые продукты
openSUSE Leap 15.0:libpython3_6m1_0-3.6.9-lp150.2.14.1
openSUSE Leap 15.0:libpython3_6m1_0-32bit-3.6.9-lp150.2.14.1
openSUSE Leap 15.0:python3-3.6.9-lp150.2.14.1
openSUSE Leap 15.0:python3-32bit-3.6.9-lp150.2.14.1

Ссылки

Описание

The documentation XML-RPC server in Python through 2.7.16, 3.x through 3.6.9, and 3.7.x through 3.7.4 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server.


Затронутые продукты
openSUSE Leap 15.0:libpython3_6m1_0-3.6.9-lp150.2.14.1
openSUSE Leap 15.0:libpython3_6m1_0-32bit-3.6.9-lp150.2.14.1
openSUSE Leap 15.0:python3-3.6.9-lp150.2.14.1
openSUSE Leap 15.0:python3-32bit-3.6.9-lp150.2.14.1

Ссылки
Уязвимость openSUSE-SU-2019:2453-1