Security update for python36
This update for python36 fixes the following issues: - Update to 3.6.15: - CVE-2021-3737: Fixed a DoS caused by infinitely reading potential HTTP headers after a 100 Continue status response from the server. (bsc#1189241) - CVE-2021-3426: Fixed an information disclosure via pydoc. (bsc#1183374) - CVE-2021-3733: Fixed a ReDoS in urllib.request. (bsc#1189287)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python36 fixes the following issues: - Update to 3.6.15: - CVE-2021-3737: Fixed a DoS caused by infinitely reading potential HTTP headers after a 100 Continue status response from the server. (bsc#1189241) - CVE-2021-3426: Fixed an information disclosure via pydoc. (bsc#1183374) - CVE-2021-3733: Fixed a ReDoS in urllib.request. (bsc#1189287)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1180125
- https://bugzilla.suse.com/1183374
- https://bugzilla.suse.com/1183858
- https://bugzilla.suse.com/1185588
- https://bugzilla.suse.com/1189241
- https://bugzilla.suse.com/1189287
- https://www.suse.com/security/cve/CVE-2021-3426
- https://www.suse.com/security/cve/CVE-2021-3733
- https://www.suse.com/security/cve/CVE-2021-3737
- https://www.suse.com/support/update/announcement/2021/suse-su-20213486-1/