shield
Security update for python3
SUSE-SLE-Module-Web-Scripting-12-2016-1558
This update provides Python 3.4.5, which brings many fixes and enhancements. The following security issues have been fixed: - CVE-2016-1000110: CGIHandler could have allowed setting of HTTP_PROXY environment variable based on user supplied Proxy request header. (bsc#989523) - CVE-2016-0772: A vulnerability in smtplib could have allowed a MITM attacker to perform a startTLS stripping attack. (bsc#984751) - CVE-2016-5636: A heap overflow in Python's zipimport module. (bsc#985177) - CVE-2016-5699: A header injection flaw in urrlib2/urllib/httplib/http.client. (bsc#985348) The update also includes the following non-security fixes: - Don't force 3rd party C extensions to be built with -Werror=declaration-after-statement. (bsc#951166) - Make urllib proxy var handling behave as usual on POSIX. (bsc#983582) For a comprehensive list of changes please refer to the upstream change log: https://docs.python.org/3.4/whatsnew/changelog.html
-
Release DateOct 26 2016
-
ReferencesBugzilla: 991069, 951166, 983582, 984751, 989523, 985177, 985348
CVEs: CVE-2016-1000110, CVE-2016-0772, CVE-2016-5636, CVE-2016-5699 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
Web and Scripting Module 12 s390x
-
Packageslibpython3_4m1_0
Python Interpreter shared librarypython33.4.5-17.1 lock rpm
Python3 Interpreterpython3-base3.4.5-17.1 lock rpm lock src
Python3 Interpreter3.4.5-17.1 lock rpm lock src
Web and Scripting Module 12 x86_64
-
Packageslibpython3_4m1_0
Python Interpreter shared librarypython33.4.5-17.1 lock rpm
Python3 Interpreterpython3-base3.4.5-17.1 lock rpm lock src
Python3 Interpreter3.4.5-17.1 lock rpm lock src
Web and Scripting Module 12 ppc64le
-
Packageslibpython3_4m1_0
Python Interpreter shared librarypython33.4.5-17.1 lock rpm
Python3 Interpreterpython3-base3.4.5-17.1 lock rpm lock src
Python3 Interpreter3.4.5-17.1 lock rpm lock src