Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202104-04 ] Python: Multiple vulnerabilities
Date: Sat, 01 May 2021 00:06:18
Message-Id: 3b48a545-01a1-4e83-db66-34389ebaf1e3@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202104-04
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Python: Multiple vulnerabilities
9 Date: April 30, 2021
10 Bugs: #770853, #779841, #779844
11 ID: 202104-04
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Python, the worst of which
19 might allow attackers to access sensitive information.
20
21 Background
22 ==========
23
24 Python is an interpreted, interactive, object-oriented programming
25 language.
26
27 Affected packages
28 =================
29
30 -------------------------------------------------------------------
31 Package / Vulnerable / Unaffected
32 -------------------------------------------------------------------
33 1 dev-lang/python < 3.9.2_p1 >= 2.7.18_p8:2.7
34 >= 3.6.13_p1:3.6
35 >= 3.7.10_p1:3.7
36 >= 3.8.8_p1:3.8
37 >= 3.9.2_p1:3.9
38
39 Description
40 ===========
41
42 Multiple vulnerabilities have been discovered in Python. Please review
43 the CVE identifiers referenced below for details.
44
45 Impact
46 ======
47
48 Please review the referenced CVE identifiers for details.
49
50 Workaround
51 ==========
52
53 There is no known workaround at this time.
54
55 Resolution
56 ==========
57
58 All Python 2.7 users should upgrade to the latest version:
59
60 # emerge --sync
61 # emerge --ask --oneshot --verbose ">=dev-lang/python-2.7.18_p8"
62
63 All Python 3.6 users should upgrade to the latest version:
64
65 # emerge --sync
66 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.6.13_p1"
67
68 All Python 3.7 users should upgrade to the latest version:
69
70 # emerge --sync
71 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.7.10_p1"
72
73 All Python 3.8 users should upgrade to the latest version:
74
75 # emerge --sync
76 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.8.8_p1"
77
78 All Python 3.9 users should upgrade to the latest version:
79
80 # emerge --sync
81 # emerge --ask --oneshot --verbose ">=dev-lang/python-3.9.2_p1"
82
83 References
84 ==========
85
86 [ 1 ] CVE-2021-23336
87 https://nvd.nist.gov/vuln/detail/CVE-2021-23336
88 [ 2 ] CVE-2021-3426
89 https://nvd.nist.gov/vuln/detail/CVE-2021-3426
90
91 Availability
92 ============
93
94 This GLSA and any updates to it are available for viewing at
95 the Gentoo Security Website:
96
97 https://security.gentoo.org/glsa/202104-04
98
99 Concerns?
100 =========
101
102 Security is a primary focus of Gentoo Linux and ensuring the
103 confidentiality and security of our users' machines is of utmost
104 importance to us. Any security concerns should be addressed to
105 security@g.o or alternatively, you may file a bug at
106 https://bugs.gentoo.org.
107
108 License
109 =======
110
111 Copyright 2021 Gentoo Foundation, Inc; referenced text
112 belongs to its owner(s).
113
114 The contents of this document are licensed under the
115 Creative Commons - Attribution / Share Alike license.
116
117 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
OpenPGP_signature.asc application/pgp-signature