OPENSUSE-SU-2022:1091-1
Not scored
Security update for python
This update for python fixes the following issues: - CVE-2022-0391: Fixed URL sanitization containing ASCII newline and tabs in urlparse (bsc#1195396). - CVE-2021-4189: Fixed ftplib not to trust the PASV response (bsc#1194146). - CVE-2021-3572: Fixed an improper handling of unicode characters in pip (bsc#1186819).
Exploit probability
Not scored
Published
April 1, 2022
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
openSUSE-SU-2022:1091-1
View original source
This update for python fixes the following issues: - CVE-2022-0391: Fixed URL sanitization containing ASCII newline and tabs in urlparse (bsc#1195396). - CVE-2021-4189: Fixed ftplib not to trust the PASV response (bsc#1194146). - CVE-2021-3572: Fixed an improper handling of unicode characters in pip (bsc#1186819).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1175619
- https://bugzilla.suse.com/1186819
- https://bugzilla.suse.com/1194146
- https://bugzilla.suse.com/1195396
- https://lists.opensuse.org/archives/list/[email protected]/thread/ULIK4RFHGHTVVWROQ6NTBBB4JWOGWYD6/
- https://www.suse.com/security/cve/CVE-2021-3572
- https://www.suse.com/security/cve/CVE-2021-4189
- https://www.suse.com/security/cve/CVE-2022-0391