Summary: | <dev-lang/python-{2.7.18-r5,3.6.12-r1,3.7.9-r1,3.8.6-r1,3.9.0-r1}: Multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | mgorny, python |
Priority: | Normal | Keywords: | CC-ARCHES |
Version: | unspecified | Flags: | nattka:
sanity-check+
|
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | A3 [glsa+] | ||
Package list: |
dev-lang/python-2.7.18-r5
dev-lang/python-3.6.12-r1
dev-lang/python-3.7.9-r1
dev-lang/python-3.8.6-r1
dev-lang/python-3.9.0-r1
|
Runtime testing required: | --- |
Bug Depends on: | |||
Bug Blocks: | 749339 |
Description
Sam James
2020-12-14 08:13:09 UTC
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=7e0543eea856397adc374bca528168179ef006d3 commit 7e0543eea856397adc374bca528168179ef006d3 Author: Michał Górny <mgorny@gentoo.org> AuthorDate: 2020-12-14 10:35:52 +0000 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: 2020-12-14 11:12:10 +0000 dev-lang/python: Backport security fixes to 3.6.12 Bug: https://bugs.gentoo.org/759928 Signed-off-by: Michał Górny <mgorny@gentoo.org> dev-lang/python/Manifest | 1 + dev-lang/python/python-3.6.12-r1.ebuild | 365 ++++++++++++++++++++++++++++++++ 2 files changed, 366 insertions(+) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=c446bebe8431bd445c4399d7cce80bfae34b6fbc commit c446bebe8431bd445c4399d7cce80bfae34b6fbc Author: Michał Górny <mgorny@gentoo.org> AuthorDate: 2020-12-14 10:32:11 +0000 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: 2020-12-14 11:12:09 +0000 dev-lang/python: Backport security fixes to 3.9.0 Bug: https://bugs.gentoo.org/759928 Signed-off-by: Michał Górny <mgorny@gentoo.org> dev-lang/python/Manifest | 1 + dev-lang/python/python-3.9.0-r1.ebuild | 331 +++++++++++++++++++++++++++++++++ 2 files changed, 332 insertions(+) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=15efabfeb80aee4b02aa97d1ea24a477ced9be12 commit 15efabfeb80aee4b02aa97d1ea24a477ced9be12 Author: Michał Górny <mgorny@gentoo.org> AuthorDate: 2020-12-14 10:30:26 +0000 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: 2020-12-14 11:12:08 +0000 dev-lang/python: Backport security fixes to 3.8.6-r1 Bug: https://bugs.gentoo.org/759928 Signed-off-by: Michał Górny <mgorny@gentoo.org> dev-lang/python/Manifest | 1 + dev-lang/python/python-3.8.6-r1.ebuild | 355 +++++++++++++++++++++++++++++++++ 2 files changed, 356 insertions(+) https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5668e86447b97b15276b7123f77fe320041f6994 commit 5668e86447b97b15276b7123f77fe320041f6994 Author: Michał Górny <mgorny@gentoo.org> AuthorDate: 2020-12-14 10:04:50 +0000 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: 2020-12-14 11:12:07 +0000 dev-lang/python: Backport security fixes to 3.7.9-r1 Bug: https://bugs.gentoo.org/759928 Signed-off-by: Michał Górny <mgorny@gentoo.org> dev-lang/python/Manifest | 1 + dev-lang/python/python-3.7.9-r1.ebuild | 351 +++++++++++++++++++++++++++++++++ 2 files changed, 352 insertions(+) I'm still working on 2.7 backport. Let's stabilize all of them once it's done. Unable to check for sanity:
> no match for package: dev-lang/python-2.7.18-r5
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=d090edd7ee7d0db0dcbe7dd4a11699e03d0141ef commit d090edd7ee7d0db0dcbe7dd4a11699e03d0141ef Author: Michał Górny <mgorny@gentoo.org> AuthorDate: 2020-12-14 12:12:19 +0000 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: 2020-12-14 12:28:54 +0000 dev-lang/python: Backport security fixes to 2.7.18-r5 Bug: https://bugs.gentoo.org/759928 Signed-off-by: Michał Górny <mgorny@gentoo.org> dev-lang/python/Manifest | 1 + dev-lang/python/python-2.7.18-r5.ebuild | 369 ++++++++++++++++++++++++++++++++ 2 files changed, 370 insertions(+) All sanity-check issues have been resolved x86 stable I'll unCC prefix as they bumped already (very quickly) to avoid noise on the alias. https://gitweb.gentoo.org/repo/proj/prefix.git/commit/?id=328cea82f46a45f4f805074ddae6d216627eba0f arm{,64} stable hppa stable ppc done sparc stable amd64 done ppc64 done s390 is running now (manually b/c of hangs) The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1d87bc85c543ce07379c1cebc5006bae8a607589 commit 1d87bc85c543ce07379c1cebc5006bae8a607589 Author: Michał Górny <mgorny@gentoo.org> AuthorDate: 2021-01-04 09:44:55 +0000 Commit: Michał Górny <mgorny@gentoo.org> CommitDate: 2021-01-04 09:45:47 +0000 dev-lang/python: Remove old Bug: https://bugs.gentoo.org/759928 Signed-off-by: Michał Górny <mgorny@gentoo.org> dev-lang/python/Manifest | 11 - dev-lang/python/python-2.7.18-r4.ebuild | 369 -------------------------------- dev-lang/python/python-3.6.11-r2.ebuild | 365 ------------------------------- dev-lang/python/python-3.6.12.ebuild | 365 ------------------------------- dev-lang/python/python-3.7.8-r2.ebuild | 351 ------------------------------ dev-lang/python/python-3.7.9.ebuild | 351 ------------------------------ dev-lang/python/python-3.8.4-r1.ebuild | 346 ------------------------------ dev-lang/python/python-3.8.5.ebuild | 355 ------------------------------ dev-lang/python/python-3.8.6.ebuild | 355 ------------------------------ dev-lang/python/python-3.9.0.ebuild | 331 ---------------------------- 10 files changed, 3199 deletions(-) s390 done all arches done This issue was resolved and addressed in GLSA 202101-18 at https://security.gentoo.org/glsa/202101-18 by GLSA coordinator Aaron Bauman (b-man). |