Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 779844 - <dev-lang/python-2.7.18_p8: multiple vulnerabilities
Summary: <dev-lang/python-2.7.18_p8: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: A4 [glsa+ cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-04-02 23:31 UTC by Michał Górny
Modified: 2021-05-01 00:01 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2021-04-02 23:31:44 UTC
These two py3 patches need non-trivial backporting to py2:

bpo-42988: CVE-2021-3426: Remove the getfile feature of the pydoc module which could be abused to read arbitrary files on the disk (directory traversal vulnerability). Moreover, even source code of Python modules can contain sensitive data like passwords. Vulnerability reported by David Schwörer.

bpo-43285: ftplib no longer trusts the IP address value returned from the server in response to the PASV command by default. This prevents a malicious FTP server from using the response to probe IPv4 address and port combinations on the client network.
Comment 1 NATTkA bot gentoo-dev 2021-04-02 23:32:21 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-04-03 07:56:21 UTC Comment hidden (obsolete)
Comment 3 Sam James archtester gentoo-dev Security 2021-04-03 22:17:24 UTC
ppc64 done
Comment 4 Sam James archtester gentoo-dev Security 2021-04-03 22:17:28 UTC
ppc done
Comment 5 Rolf Eike Beer 2021-04-04 13:08:30 UTC
sparc stable
Comment 6 Thomas Deutschmann gentoo-dev Security 2021-04-04 16:04:10 UTC
x86 stable
Comment 7 Rolf Eike Beer 2021-04-05 09:17:03 UTC
hppa stable
Comment 8 Sam James archtester gentoo-dev Security 2021-04-07 06:21:28 UTC
arm64 done
Comment 9 Sam James archtester gentoo-dev Security 2021-04-11 17:01:13 UTC
arm done
Comment 10 Sam James archtester gentoo-dev Security 2021-04-12 01:34:59 UTC
amd64 done

all arches done
Comment 11 John Helmert III gentoo-dev Security 2021-04-12 13:12:27 UTC
Please cleanup.
Comment 12 Larry the Git Cow gentoo-dev 2021-04-12 20:26:32 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=834f7d0e6ec7cc60835539a4114edbc4bd0e8930

commit 834f7d0e6ec7cc60835539a4114edbc4bd0e8930
Author:     Michał Górny <mgorny@gentoo.org>
AuthorDate: 2021-04-12 20:23:04 +0000
Commit:     Michał Górny <mgorny@gentoo.org>
CommitDate: 2021-04-12 20:26:05 +0000

    dev-lang/python: Remove old
    
    Bug: https://bugs.gentoo.org/779841
    Bug: https://bugs.gentoo.org/779844
    Signed-off-by: Michał Górny <mgorny@gentoo.org>

 dev-lang/python/Manifest                       |  11 -
 dev-lang/python/python-2.7.18_p7.ebuild        | 358 -------------------------
 dev-lang/python/python-3.10.0_alpha6-r2.ebuild | 350 ------------------------
 dev-lang/python/python-3.6.13.ebuild           | 341 -----------------------
 dev-lang/python/python-3.7.10.ebuild           | 333 -----------------------
 dev-lang/python/python-3.8.8.ebuild            | 339 -----------------------
 dev-lang/python/python-3.9.2.ebuild            | 348 ------------------------
 dev-lang/python/python-3.9.3.ebuild            | 348 ------------------------
 8 files changed, 2428 deletions(-)
Comment 13 Thomas Deutschmann gentoo-dev Security 2021-04-30 23:28:34 UTC
Added to an existing GLSA request.
Comment 14 GLSAMaker/CVETool Bot gentoo-dev 2021-05-01 00:01:45 UTC
This issue was resolved and addressed in
 GLSA 202104-04 at https://security.gentoo.org/glsa/202104-04
by GLSA coordinator Thomas Deutschmann (whissi).