Lucene search

K
rockyRockylinux Product ErrataRLSA-2024:3275
HistoryJun 14, 2024 - 1:59 p.m.

python-dns security update

2024-06-1413:59:16
Rockylinux Product Errata
errata.rockylinux.org
55
python-dns
security update
rocky linux 8
cve-2023-29483
denial of service
dns client
cvss
vulnerability
dnspython
stub resolver

CVSS3

7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

13.0%

An update is available for python-dns.
This update affects Rocky Linux 8.
A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list
The python-dns package contains the dnslib module that implements a DNS client and additional modules that define certain symbolic constants used by DNS, such as dnstype, dnsclass and dnsopcode.

Security Fix(es):

  • dnspython: denial of service in stub resolver (CVE-2023-29483)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

OSVersionArchitecturePackageVersionFilename
rocky8noarchpython3-dns< 1.15.0-12.el8_10python3-dns-0:1.15.0-12.el8_10.noarch.rpm

CVSS3

7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

AI Score

6.8

Confidence

Low

EPSS

0

Percentile

13.0%