Oval Definition:oval:org.opensuse.security:def:63941
Revision Date:2020-12-01Version:1
Title:Security update for python (Moderate)
Description:





This update for python to version 2.7.17 fixes the following issues:

Syncing with lots of upstream bug fixes and security fixes.

Bug fixes:

- CVE-2019-9674: Improved the documentation to reflect the dangers of zip-bombs (bsc#1162825). - CVE-2019-18348: Fixed a CRLF injection via the host part of the url passed to urlopen(). Now an InvalidURL exception is raised (bsc#1155094). - CVE-2020-8492: Fixed a regular expression in urllib that was prone to denial of service via HTTP (bsc#1162367). - Fixed mismatches between libpython and python-base versions (bsc#1162224). - Fixed segfault in libpython2.7.so.1 (bsc#1073748). - Unified packages among openSUSE:Factory and SLE versions (bsc#1159035). - Added idle.desktop and idle.appdata.xml to provide IDLE in menus (bsc#1153830). - Excluded tsl_check files from python-base to prevent file conflict with python-strict-tls-checks package (bsc#945401). - Changed the name of idle3 icons to idle3.png to avoid collision with Python 2 version (bsc#1165894).

Additionally a new 'shared-python-startup' package is provided containing startup files.

python-rpm-macros was updated to fix:

- Do not write .pyc files for tests (bsc#1171561)

Family:unixClass:patch
Status:Reference(s):1027282
1041090
1042670
1073269
1073748
1078326
1078485
1081750
1084650
1086001
1109957
1112959
1118896
1126503
1129071
1132663
1132900
1146608
1149792
1153830
1155094
1159035
1162224
1162367
1162825
1165894
1166238
1168994
1170411
1170940
1171561
1171883
1173576
1173613
1173812
1174463
1174570
1176733
945401
CVE-2018-16837
CVE-2018-16859
CVE-2018-16876
CVE-2019-11236
CVE-2019-11324
CVE-2019-14973
CVE-2019-18348
CVE-2019-3828
CVE-2019-9674
CVE-2019-9740
CVE-2020-10713
CVE-2020-12402
CVE-2020-12415
CVE-2020-12416
CVE-2020-12417
CVE-2020-12418
CVE-2020-12419
CVE-2020-12420
CVE-2020-12421
CVE-2020-12422
CVE-2020-12423
CVE-2020-12424
CVE-2020-12425
CVE-2020-12426
CVE-2020-14308
CVE-2020-14309
CVE-2020-14310
CVE-2020-14311
CVE-2020-15706
CVE-2020-15707
CVE-2020-1983
CVE-2020-26117
CVE-2020-8492
openSUSE-SU-2019:1635-1
openSUSE-SU-2019:2133-1
openSUSE-SU-2020:0636-1
openSUSE-SU-2020:1017-1
openSUSE-SU-2020:1561-1
SUSE-SU-2020:0854-1
SUSE-SU-2020:1524-1
SUSE-SU-2020:1857-1
SUSE-SU-2020:2078-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND ansible-2.8.1-12 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libtiff-devel-4.0.9-lp152.11.3 is installed
  • OR libtiff-devel-32bit-4.0.9-lp152.11.3 is installed
  • OR libtiff5-4.0.9-lp152.11.3 is installed
  • OR libtiff5-32bit-4.0.9-lp152.11.3 is installed
  • OR tiff-4.0.9-lp152.11.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • libpython2_7-1_0-2.7.17-28.42 is installed
  • OR libpython2_7-1_0-32bit-2.7.17-28.42 is installed
  • OR python-2.7.17-28.42 is installed
  • OR python-32bit-2.7.17-28.42 is installed
  • OR python-base-2.7.17-28.42 is installed
  • OR python-base-32bit-2.7.17-28.42 is installed
  • OR python-curses-2.7.17-28.42 is installed
  • OR python-demo-2.7.17-28.42 is installed
  • OR python-devel-2.7.17-28.42 is installed
  • OR python-doc-2.7.17-28.42 is installed
  • OR python-doc-pdf-2.7.17-28.42 is installed
  • OR python-gdbm-2.7.17-28.42 is installed
  • OR python-idle-2.7.17-28.42 is installed
  • OR python-rpm-macros-20200207.5feb6c1-3.19 is installed
  • OR python-tk-2.7.17-28.42 is installed
  • OR python-xml-2.7.17-28.42 is installed
  • OR shared-python-startup-0.1-1.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • libXvnc1-1.6.0-22.17 is installed
  • OR tigervnc-1.6.0-22.17 is installed
  • OR xorg-x11-Xvnc-1.6.0-22.17 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • grub2-2.02-12.31 is installed
  • OR grub2-arm64-efi-2.02-12.31 is installed
  • OR grub2-i386-pc-2.02-12.31 is installed
  • OR grub2-powerpc-ieee1275-2.02-12.31 is installed
  • OR grub2-s390x-emu-2.02-12.31 is installed
  • OR grub2-snapper-plugin-2.02-12.31 is installed
  • OR grub2-systemd-sleep-plugin-2.02-12.31 is installed
  • OR grub2-x86_64-efi-2.02-12.31 is installed
  • OR grub2-x86_64-xen-2.02-12.31 is installed
  • BACK