gpp_maybe
Security update for python3
SUSE-SLE-Module-Development-Tools-15-SP5-2024-3470
This update for python3 fixes the following issues: - CVE-2024-6923: Fixed uncontrolled CPU resource consumption when in http.cookies module (bsc#1228780). - CVE-2024-5642: Fixed buffer overread when NPN is used and invalid values are sent to the OpenSSL API (bsc#1227233). - CVE-2024-7592: Fixed Email header injection due to unquoted newlines (bsc#1229596). - CVE-2024-6232: excessive backtracking when parsing tarfile headers leads to ReDoS. (bsc#1230227) Bug fixes: - %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999). - Stop using %%defattr, it seems to be breaking proper executable attributes on /usr/bin/ scripts (bsc#1227378). - Remove %suse_update_desktop_file macro as it is not useful any more.
-
Release DateSep 27 2024
-
ReferencesBugzilla: 1230227, 1228780, 1227233, 1227378, 1229596, 1227999
CVEs: CVE-2024-6923, CVE-2024-5642, CVE-2024-7592, CVE-2024-6232 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Development Tools Module 15.5 s390x
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.72.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.72.1 lock rpm
Development Tools Module 15.5 aarch64
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.72.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.72.1 lock rpm
Development Tools Module 15.5 ppc64le
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.72.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.72.1 lock rpm
Development Tools Module 15.5 x86_64
-
Packagespython3-core
Python 3 Interpreterpython3-tools3.6.15-150300.10.72.1 lock src
Python Utility and Demonstration Scripts3.6.15-150300.10.72.1 lock rpm