FlawAtlas
Search the atlas
SUSE-SU-2020:3563-1 Not scored

Security update for python36

This update for python36 fixes the following issues: Update to 3.6.12, including the following fixes: - Fixed a directory traversal in _download_http_url() (bsc#1176262 CVE-2019-20916) - Fixed CRLF injection via HTTP request method in httplib/http.client (bsc#1177211 CVE-2020-26116) - Fixed possible infinite loop in specifically crafted tarball (bsc#1174091 CVE-2019-20907) - Fixed a CRLF injection via the host part of the url passed to urlopen() (bsc#1155094 CVE-2019-18348) - Reamed idle icons to idle3 in order to avoid conflicts with python2 (bsc#1165894) - Handful of compatibility changes between SLE15 and SLE12 (jsc#ECO-2799, jsc#SLE-13738, bsc#1179193)

Exploit probability Not scored
Published November 30, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP5 python36
SUSE:Linux Enterprise Server 12 SP5 python36-core
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python36
SUSE:Linux Enterprise Server for SAP Applications 12 SP5 python36-core

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2020:3563-1

This update for python36 fixes the following issues: Update to 3.6.12, including the following fixes: - Fixed a directory traversal in _download_http_url() (bsc#1176262 CVE-2019-20916) - Fixed CRLF injection via HTTP request method in httplib/http.client (bsc#1177211 CVE-2020-26116) - Fixed possible infinite loop in specifically crafted tarball (bsc#1174091 CVE-2019-20907) - Fixed a CRLF injection via the host part of the url passed to urlopen() (bsc#1155094 CVE-2019-18348) - Reamed idle icons to idle3 in order to avoid conflicts with python2 (bsc#1165894) - Handful of compatibility changes between SLE15 and SLE12 (jsc#ECO-2799, jsc#SLE-13738, bsc#1179193)

View original source

05 / REFERENCES

Further evidence