Moderate: python27:2.7 security update
Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing. The python27 packages provide a stable release of Python 2.7 with a number of additional utilities and database connectors for MySQL and PostgreSQL. Security Fix(es): * pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py (CVE-2022-40897) * python: use after free in heappushpop() of heapq module (CVE-2022-48560) * python: XML External Entity in XML processing plistlib module (CVE-2022-48565) * python-urllib3: Cookie request header isn't stripped during cross-origin redirects (CVE-2023-43804) * jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing. The python27 packages provide a stable release of Python 2.7 with a number of additional utilities and database connectors for MySQL and PostgreSQL. Security Fix(es): * pypa-setuptools: Regular Expression Denial of Service (ReDoS) in package_index.py (CVE-2022-40897) * python: use after free in heappushpop() of heapq module (CVE-2022-48560) * python: XML External Entity in XML processing plistlib module (CVE-2022-48565) * python-urllib3: Cookie request header isn't stripped during cross-origin redirects (CVE-2023-43804) * jinja2: HTML attribute injection when passing user input as keys to xmlattr filter (CVE-2024-22195) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2024:2987
- https://access.redhat.com/security/cve/CVE-2022-40897
- https://access.redhat.com/security/cve/CVE-2022-48560
- https://access.redhat.com/security/cve/CVE-2022-48565
- https://access.redhat.com/security/cve/CVE-2023-43804
- https://access.redhat.com/security/cve/CVE-2024-22195
- https://bugzilla.redhat.com/2158559
- https://bugzilla.redhat.com/2240059
- https://bugzilla.redhat.com/2242493
- https://bugzilla.redhat.com/2249755
- https://bugzilla.redhat.com/2257854
- https://errata.almalinux.org/8/ALSA-2024-2987.html