Security update for python3
This update for python3 fixes the following issues: - CVE-2019-10160: Fixed a regression in urlparse() and urlsplit() introduced by the fix for CVE-2019-9636 (bsc#1138459). - CVE-2018-14647: Fixed a denial of service vulnerability caused by a crafted XML document (bsc#1109847). - CVE-2018-1000802: Fixed a command injection in the shutil module (bsc#1109663).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python3 fixes the following issues: - CVE-2019-10160: Fixed a regression in urlparse() and urlsplit() introduced by the fix for CVE-2019-9636 (bsc#1138459). - CVE-2018-14647: Fixed a denial of service vulnerability caused by a crafted XML document (bsc#1109847). - CVE-2018-1000802: Fixed a command injection in the shutil module (bsc#1109663).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1109663
- https://bugzilla.suse.com/1109847
- https://bugzilla.suse.com/1138459
- https://www.suse.com/security/cve/CVE-2018-1000802
- https://www.suse.com/security/cve/CVE-2018-14647
- https://www.suse.com/security/cve/CVE-2019-10160
- https://www.suse.com/support/update/announcement/2019/suse-su-20192053-2/