Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 779844

Summary: <dev-lang/python-2.7.18_p8: multiple vulnerabilities
Product: Gentoo Security Reporter: Michał Górny <mgorny>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: python
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
See Also: https://bugs.gentoo.org/show_bug.cgi?id=779841
Whiteboard: A4 [glsa+ cve]
Package list:
Runtime testing required: ---

Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2021-04-02 23:31:44 UTC
These two py3 patches need non-trivial backporting to py2:

bpo-42988: CVE-2021-3426: Remove the getfile feature of the pydoc module which could be abused to read arbitrary files on the disk (directory traversal vulnerability). Moreover, even source code of Python modules can contain sensitive data like passwords. Vulnerability reported by David Schwörer.

bpo-43285: ftplib no longer trusts the IP address value returned from the server in response to the PASV command by default. This prevents a malicious FTP server from using the response to probe IPv4 address and port combinations on the client network.
Comment 1 NATTkA bot gentoo-dev 2021-04-02 23:32:21 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-04-03 07:56:21 UTC Comment hidden (obsolete)
Comment 3 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-03 22:17:24 UTC
ppc64 done
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-03 22:17:28 UTC
ppc done
Comment 5 Rolf Eike Beer archtester 2021-04-04 13:08:30 UTC
sparc stable
Comment 6 Thomas Deutschmann (RETIRED) gentoo-dev 2021-04-04 16:04:10 UTC
x86 stable
Comment 7 Rolf Eike Beer archtester 2021-04-05 09:17:03 UTC
hppa stable
Comment 8 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-07 06:21:28 UTC
arm64 done
Comment 9 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-11 17:01:13 UTC
arm done
Comment 10 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-04-12 01:34:59 UTC
amd64 done

all arches done
Comment 11 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-04-12 13:12:27 UTC
Please cleanup.
Comment 12 Larry the Git Cow gentoo-dev 2021-04-12 20:26:32 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=834f7d0e6ec7cc60835539a4114edbc4bd0e8930

commit 834f7d0e6ec7cc60835539a4114edbc4bd0e8930
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2021-04-12 20:23:04 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2021-04-12 20:26:05 +0000

    dev-lang/python: Remove old
    
    Bug: https://bugs.gentoo.org/779841
    Bug: https://bugs.gentoo.org/779844
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 dev-lang/python/Manifest                       |  11 -
 dev-lang/python/python-2.7.18_p7.ebuild        | 358 -------------------------
 dev-lang/python/python-3.10.0_alpha6-r2.ebuild | 350 ------------------------
 dev-lang/python/python-3.6.13.ebuild           | 341 -----------------------
 dev-lang/python/python-3.7.10.ebuild           | 333 -----------------------
 dev-lang/python/python-3.8.8.ebuild            | 339 -----------------------
 dev-lang/python/python-3.9.2.ebuild            | 348 ------------------------
 dev-lang/python/python-3.9.3.ebuild            | 348 ------------------------
 8 files changed, 2428 deletions(-)
Comment 13 Thomas Deutschmann (RETIRED) gentoo-dev 2021-04-30 23:28:34 UTC
Added to an existing GLSA request.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2021-05-01 00:01:45 UTC
This issue was resolved and addressed in
 GLSA 202104-04 at https://security.gentoo.org/glsa/202104-04
by GLSA coordinator Thomas Deutschmann (whissi).