Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 835443

Summary: <dev-lang/python-{3.10.3,3.9.11,3.8.13,3.7.13}: multiple vulnerabilities
Product: Gentoo Security Reporter: Michał Górny <mgorny>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: python
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://www.python.org/downloads/release/python-3911/
Whiteboard: A3 [glsa+]
Package list:
Runtime testing required: ---
Bug Depends on: 835444, 835445, 835446, 835447    
Bug Blocks: 835609    

Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-03-16 19:03:47 UTC
Mostly through upgrading bundled libs that don't affect us but also:

- CVE-2021-28363: bundled pip upgraded from 21.2.4 to 22.0.4 (BPO-46985)
- authorization bypass fixed in urllib.request (BPO-46756)
- REDoS avoided in importlib.metadata (BPO-46474)
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-19 04:22:03 UTC
Thank you for reporting!
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-19 01:15:30 UTC
GLSA requested
Comment 3 Larry the Git Cow gentoo-dev 2023-05-03 09:31:54 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=721dfacf17914fe5f7bfa3d0b401379d6318f7b1

commit 721dfacf17914fe5f7bfa3d0b401379d6318f7b1
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-05-03 09:12:43 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-05-03 09:31:45 +0000

    [ GLSA 202305-02 ] Python, PyPy3: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/787260
    Bug: https://bugs.gentoo.org/793833
    Bug: https://bugs.gentoo.org/811165
    Bug: https://bugs.gentoo.org/834533
    Bug: https://bugs.gentoo.org/835443
    Bug: https://bugs.gentoo.org/838250
    Bug: https://bugs.gentoo.org/864747
    Bug: https://bugs.gentoo.org/876815
    Bug: https://bugs.gentoo.org/877851
    Bug: https://bugs.gentoo.org/878385
    Bug: https://bugs.gentoo.org/880629
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202305-02.xml | 107 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 107 insertions(+)