Security update for python3
This update for python3 fixes the following issues: - CVE-2021-3426: Fixed information disclosure via pydoc (bsc#1183374). - CVE-2021-3733: Fixed infinitely reading potential HTTP headers after a 100 Continue status response from the server (bsc#1189241). - CVE-2021-3737: Fixed ReDoS in urllib.request (bsc#1189287). - We do not require python-rpm-macros package (bsc#1180125). - Use versioned python-Sphinx to avoid dependency on other version of Python (bsc#1183858). - Stop providing 'python' symbol, which means python2 currently (bsc#1185588). - Modify Lib/ensurepip/__init__.py to contain the same version numbers as are in reality the ones in the bundled wheels (bsc#1187668).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python3 fixes the following issues: - CVE-2021-3426: Fixed information disclosure via pydoc (bsc#1183374). - CVE-2021-3733: Fixed infinitely reading potential HTTP headers after a 100 Continue status response from the server (bsc#1189241). - CVE-2021-3737: Fixed ReDoS in urllib.request (bsc#1189287). - We do not require python-rpm-macros package (bsc#1180125). - Use versioned python-Sphinx to avoid dependency on other version of Python (bsc#1183858). - Stop providing 'python' symbol, which means python2 currently (bsc#1185588). - Modify Lib/ensurepip/__init__.py to contain the same version numbers as are in reality the ones in the bundled wheels (bsc#1187668).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1180125
- https://bugzilla.suse.com/1183374
- https://bugzilla.suse.com/1183858
- https://bugzilla.suse.com/1185588
- https://bugzilla.suse.com/1187668
- https://bugzilla.suse.com/1189241
- https://bugzilla.suse.com/1189287
- https://lists.opensuse.org/archives/list/[email protected]/thread/KYXM7YGLJSNOU4FYI3M2QXACCQ4SO3AE/
- https://www.suse.com/security/cve/CVE-2021-3426
- https://www.suse.com/security/cve/CVE-2021-3733
- https://www.suse.com/security/cve/CVE-2021-3737