Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 835443 - <dev-lang/python-{3.10.3,3.9.11,3.8.13,3.7.13}: multiple vulnerabilities
Summary: <dev-lang/python-{3.10.3,3.9.11,3.8.13,3.7.13}: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://www.python.org/downloads/rele...
Whiteboard: A3 [glsa+]
Keywords:
Depends on: 835444 835445 835446 835447
Blocks: CVE-2021-28363
  Show dependency tree
 
Reported: 2022-03-16 19:03 UTC by Michał Górny
Modified: 2023-05-03 09:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-03-16 19:03:47 UTC
Mostly through upgrading bundled libs that don't affect us but also:

- CVE-2021-28363: bundled pip upgraded from 21.2.4 to 22.0.4 (BPO-46985)
- authorization bypass fixed in urllib.request (BPO-46756)
- REDoS avoided in importlib.metadata (BPO-46474)
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-19 04:22:03 UTC
Thank you for reporting!
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-19 01:15:30 UTC
GLSA requested
Comment 3 Larry the Git Cow gentoo-dev 2023-05-03 09:31:54 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=721dfacf17914fe5f7bfa3d0b401379d6318f7b1

commit 721dfacf17914fe5f7bfa3d0b401379d6318f7b1
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-05-03 09:12:43 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-05-03 09:31:45 +0000

    [ GLSA 202305-02 ] Python, PyPy3: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/787260
    Bug: https://bugs.gentoo.org/793833
    Bug: https://bugs.gentoo.org/811165
    Bug: https://bugs.gentoo.org/834533
    Bug: https://bugs.gentoo.org/835443
    Bug: https://bugs.gentoo.org/838250
    Bug: https://bugs.gentoo.org/864747
    Bug: https://bugs.gentoo.org/876815
    Bug: https://bugs.gentoo.org/877851
    Bug: https://bugs.gentoo.org/878385
    Bug: https://bugs.gentoo.org/880629
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202305-02.xml | 107 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 107 insertions(+)