Lucene search

K
osvGoogleOSV:SUSE-SU-2024:2982-1
HistoryAug 20, 2024 - 9:08 a.m.

Security update for python311

2024-08-2009:08:57
Google
osv.dev
1
python 3.11
security update
cve-2024-6923
cve-2024-5642
cve-2024-4032
openssl
reproducible builds
pip
/usr/local
bsc#1228780
bsc#1227233
bsc#1226448
bsc#1227378
bsc#1227999
bsc#1225660
executable bits
profiling

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

Low

EPSS

0.002

Percentile

55.1%

This update for python311 fixes the following issues:

Security issues fixed:

  • CVE-2024-6923: Fixed email header injection due to unquoted newlines (bsc#1228780)
  • CVE-2024-5642: Removed support for anything but OpenSSL 1.1.1 or newer (bsc#1227233)
  • CVE-2024-4032: Fixed incorrect IPv4 and IPv6 private ranges (bsc#1226448)

Non-security issues fixed:

  • Fixed executable bits for /usr/bin/idle* (bsc#1227378).
  • Improve python reproducible builds (bsc#1227999)
  • Make pip and modern tools install directly in /usr/local when used by the user (bsc#1225660)
  • %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.4

Confidence

Low

EPSS

0.002

Percentile

55.1%