← Search the atlas
SUSE-SU-2020:0854-1
Not scored
Security update for python3
This update for python3 fixes the following issue:
- CVE-2019-18348: Fixed a CRLF injection via the host part
of the url passed to urlopen(). Now an InvalidURL exception
is raised (bsc#1155094).
- CVE-2019-9674: Improved the documentation to reflect the
dangers of zip-bombs (bsc#1162825).
- CVE-2020-8492: Fixed a regular expression in urllib that
was prone to denial of service via HTTP (bsc#1162367).
- Fixed an issue with version missmatch (bsc#1162224).
- Rename idle icons to idle3 in order to not conflict with python2
variant of the package. (bsc#1165894)
Exploit probability
Not scored
Published
April 2, 2020
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
SUSE:Linux Enterprise Server 12 SP3-LTSS
python3
SUSE:Linux Enterprise Server for SAP Applications 12 SP4
python3-base
SUSE:Linux Enterprise Server 12 SP2-LTSS
python3-base
SUSE:OpenStack Cloud 7
python3
SUSE:Linux Enterprise Server 12 SP1-LTSS
python3
SUSE:Enterprise Storage 5
python3
SUSE:HPE Helion OpenStack 8
python3
SUSE:Linux Enterprise Server 12 SP4
python3
SUSE:Linux Enterprise Server for SAP Applications 12 SP5
python3
SUSE:Linux Enterprise Server 12 SP3-BCL
python3-base
SUSE:Linux Enterprise Module for Web and Scripting 12
python3-base
SUSE:Linux Enterprise Server 12 SP2-BCL
python3
SUSE:HPE Helion OpenStack 8
python3-base
SUSE:Linux Enterprise Server for SAP Applications 12 SP4
python3
SUSE:OpenStack Cloud 7
python3-base
SUSE:OpenStack Cloud Crowbar 8
python3-base
SUSE:Linux Enterprise Server 12 SP3-LTSS
python3-base
SUSE:Linux Enterprise Server 12 SP5
python3
SUSE:Linux Enterprise Software Development Kit 12 SP4
python3
SUSE:Linux Enterprise Software Development Kit 12 SP4
python3-base
SUSE:Linux Enterprise Module for Web and Scripting 12
python3
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
python3-base
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
python3
SUSE:Linux Enterprise Server 12 SP2-LTSS
python3
SUSE:Linux Enterprise Server 12 SP3-BCL
python3
SUSE:Linux Enterprise Server for SAP Applications 12 SP1
python3-base
SUSE:Linux Enterprise Server 12 SP2-BCL
python3-base
SUSE:OpenStack Cloud 8
python3
SUSE:Linux Enterprise Server for SAP Applications 12 SP2
python3
SUSE:Linux Enterprise Software Development Kit 12 SP5
python3
SUSE:Linux Enterprise Software Development Kit 12 SP5
python3-base
SUSE:Linux Enterprise Server 12 SP1-LTSS
python3-base
SUSE:OpenStack Cloud 8
python3-base
SUSE:OpenStack Cloud Crowbar 8
python3
SUSE:Linux Enterprise Server 12 SP5
python3-base
SUSE:Linux Enterprise Server for SAP Applications 12 SP1
python3
SUSE:Linux Enterprise Server for SAP Applications 12 SP5
python3-base
SUSE:Linux Enterprise Server 12 SP4
python3-base
SUSE:Linux Enterprise Server for SAP Applications 12 SP3
python3-base
SUSE:Enterprise Storage 5
python3-base
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2020:0854-1
This update for python3 fixes the following issue:
- CVE-2019-18348: Fixed a CRLF injection via the host part
of the url passed to urlopen(). Now an InvalidURL exception
is raised (bsc#1155094).
- CVE-2019-9674: Improved the documentation to reflect the
dangers of zip-bombs (bsc#1162825).
- CVE-2020-8492: Fixed a regular expression in urllib that
was prone to denial of service via HTTP (bsc#1162367).
- Fixed an issue with version missmatch (bsc#1162224).
- Rename idle icons to idle3 in order to not conflict with python2
variant of the package. (bsc#1165894)
View original source ↗
05 / REFERENCES
Further evidence