Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 876815 - <dev-lang/python-{3.8.15,3.9.15,3.10.8,3.11.0_rc2_p1}: multiple vulnerabilities
Summary: <dev-lang/python-{3.8.15,3.9.15,3.10.8,3.11.0_rc2_p1}: multiple vulnerabilities
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://discuss.python.org/t/python-v...
Whiteboard: A3 [glsa+]
Keywords:
Depends on: 876809 876811 876813
Blocks:
  Show dependency tree
 
Reported: 2022-10-12 05:01 UTC by Michał Górny
Modified: 2023-05-03 09:35 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-10-12 05:01:34 UTC
- CVE-2022-40674: bundled libexpat was upgraded from 2.4.7 to 2.4.9 which fixes a heap use-after-free vulnerability in function doContent
- gh-97616: a fix for a possible buffer overflow in list *= int
- gh-97612: a fix for possible shell injection in the example script get-remote-certificate.py (this issue originally had a CVE assigned to it, which its author withdrew)
- gh-96577: a fix for a potential buffer overrun in msilib
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-10-12 05:03:28 UTC
3.11 is also affected but upstream didn't make a release, so I'll just cherry-pick fixes.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-10-12 14:54:16 UTC
Thanks!
Comment 3 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2022-10-13 05:09:41 UTC
Cleanup done.  It's possible that 2.7 is affected too but providing more security support for it is beyond my capabilities.
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-10-13 14:34:22 UTC
Indeed, thanks! I suppose we'll GLSA Python itself but leave off pypy for bug 868150
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-11-19 01:15:48 UTC
GLSA requested
Comment 6 Larry the Git Cow gentoo-dev 2023-05-03 09:31:56 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=721dfacf17914fe5f7bfa3d0b401379d6318f7b1

commit 721dfacf17914fe5f7bfa3d0b401379d6318f7b1
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-05-03 09:12:43 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2023-05-03 09:31:45 +0000

    [ GLSA 202305-02 ] Python, PyPy3: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/787260
    Bug: https://bugs.gentoo.org/793833
    Bug: https://bugs.gentoo.org/811165
    Bug: https://bugs.gentoo.org/834533
    Bug: https://bugs.gentoo.org/835443
    Bug: https://bugs.gentoo.org/838250
    Bug: https://bugs.gentoo.org/864747
    Bug: https://bugs.gentoo.org/876815
    Bug: https://bugs.gentoo.org/877851
    Bug: https://bugs.gentoo.org/878385
    Bug: https://bugs.gentoo.org/880629
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Sam James <sam@gentoo.org>

 glsa-202305-02.xml | 107 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 107 insertions(+)