Security update for python3
This update for python3 fixes the following issues: - CVE-2019-20907: Fixed denial of service by avoiding possible infinite loop in specifically crafted tarball (bsc#1174091). - CVE-2020-14422: Fixed an improper computation of hash values in the IPv4Interface and IPv6Interface could have led to denial of service (bsc#1173274). - CVE-2019-16935: Fixed a reflected XSS in python/Lib/DocXMLRPCServer.py (bsc#1153238). - CVE-2019-9947: Fixed an issue in urllib2 which allowed CRLF injection if the attacker controls a url parameter (bsc#1130840). - If the locale is 'C', coerce it to C.UTF-8 (bsc#1162423).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python3 fixes the following issues: - CVE-2019-20907: Fixed denial of service by avoiding possible infinite loop in specifically crafted tarball (bsc#1174091). - CVE-2020-14422: Fixed an improper computation of hash values in the IPv4Interface and IPv6Interface could have led to denial of service (bsc#1173274). - CVE-2019-16935: Fixed a reflected XSS in python/Lib/DocXMLRPCServer.py (bsc#1153238). - CVE-2019-9947: Fixed an issue in urllib2 which allowed CRLF injection if the attacker controls a url parameter (bsc#1130840). - If the locale is 'C', coerce it to C.UTF-8 (bsc#1162423).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1088004
- https://bugzilla.suse.com/1088009
- https://bugzilla.suse.com/1130840
- https://bugzilla.suse.com/1141853
- https://bugzilla.suse.com/1149955
- https://bugzilla.suse.com/1153238
- https://bugzilla.suse.com/1162423
- https://bugzilla.suse.com/1173274
- https://bugzilla.suse.com/1174091
- https://bugzilla.suse.com/1174701
- https://www.suse.com/security/cve/CVE-2018-14647
- https://www.suse.com/security/cve/CVE-2018-20852
- https://www.suse.com/security/cve/CVE-2019-16056
- https://www.suse.com/security/cve/CVE-2019-16935
- https://www.suse.com/security/cve/CVE-2019-20907
- https://www.suse.com/security/cve/CVE-2019-9947
- https://www.suse.com/security/cve/CVE-2020-14422
- https://www.suse.com/support/update/announcement/2020/suse-su-20202699-1/