Oval Definition:oval:com.redhat.rhsa:def:20230833
Revision Date:2023-02-21Version:635
Title:RHSA-2023:0833: python3 security update (Moderate)
Description:Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • python: int() type in PyLong_FromString() does not limit amount of digits converting text to int leading to DoS (CVE-2020-10735)

  • python: open redirection vulnerability in lib/http/server.py may lead to information disclosure (CVE-2021-28861)

  • Python: CPU denial of service via inefficient IDNA decoder (CVE-2022-45061)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2020-10735
    CVE-2021-28861
    CVE-2022-45061
    RHSA-2023:0833
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • platform-python is earlier than 0:3.6.8-48.el8_7.1
  • AND platform-python is signed with Red Hat redhatrelease2 key
  • platform-python-debug is earlier than 0:3.6.8-48.el8_7.1
  • AND platform-python-debug is signed with Red Hat redhatrelease2 key
  • platform-python-devel is earlier than 0:3.6.8-48.el8_7.1
  • AND platform-python-devel is signed with Red Hat redhatrelease2 key
  • python3-idle is earlier than 0:3.6.8-48.el8_7.1
  • AND python3-idle is signed with Red Hat redhatrelease2 key
  • python3-libs is earlier than 0:3.6.8-48.el8_7.1
  • AND python3-libs is signed with Red Hat redhatrelease2 key
  • python3-test is earlier than 0:3.6.8-48.el8_7.1
  • AND python3-test is signed with Red Hat redhatrelease2 key
  • python3-tkinter is earlier than 0:3.6.8-48.el8_7.1
  • AND python3-tkinter is signed with Red Hat redhatrelease2 key
  • BACK