|
|
Subscribe / Log in / New account

Mageia alert MGASA-2021-0386 (python3)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2021-0386: Updated python3 packages fix security vulnerabilities
Date:  Tue, 27 Jul 2021 22:23:10 +0200
Message-ID:  <20210727202311.04937A139B@duvel.mageia.org>
Archive-link:  Article

MGASA-2021-0386 - Updated python3 packages fix security vulnerabilities Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0386.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-29921 Description: Update python3 to 3.8.11 to fix several security issues. Fixes in 3.8.10 are also included. Bundled pip and setuptools were updated in 3.8.11 so python-pip needs to be updated to 21.1.3 and python-setuptools to 56.2.0 at the same time. Also, we fix the following issue: In Python before 3.9.5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses (CVE-2021-29921). References: - https://bugs.mageia.org/show_bug.cgi?id=29288 - https://docs.python.org/release/3.8.11/whatsnew/changelog... - https://docs.python.org/release/3.8.10/whatsnew/changelog... - https://ubuntu.com/security/notices/USN-4973-1 - https://python-security.readthedocs.io/vuln/ipaddress-ipv4-leading-zeros.html - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2... SRPMS: - 8/core/python-pip-21.1.3-1.mga8 - 8/core/python-setuptools-56.2.0-1.mga8 - 8/core/python3-3.8.11-1.1.mga8


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds