Bug 52082 - (ES 4.3) python3.5
(ES 4.3) python3.5
Status: CLOSED FIXED
Product: UCS
Classification: Unclassified
Component: Security updates
UCS 4.3
All other
: P5 normal (vote)
: ---
Assigned To: Quality Assurance
Felix Botner
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2020-09-20 21:49 CEST by Erik Damrose
Modified: 2020-11-30 12:46 CET (History)
1 user (show)

See Also:
What kind of report is it?: ---
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Erik Damrose univentionstaff 2020-09-20 21:49:10 CEST
Provide python3.5 version 3.5.3-1+deb9u2 for UCS 4.3
First imported at bug #51715

This update addresses the following issues:
* Integer overflow in Modules/_pickle.c allows for memory exhaustion if
  serializing gigabytes of data (CVE-2018-20406)
* Cookie domain check returns incorrect results (CVE-2018-20852)
* NULL pointer dereference using a specially crafted X509 certificate
  (CVE-2019-5010)
* Information Disclosure due to urlsplit improper NFKC normalization
  (CVE-2019-9636)
* Improper neutralization of CRLF sequences in urllib module (CVE-2019-9740)
* Improper neutralization of CRLF sequences in urllib module (CVE-2019-9947)
* Undocumented local_file protocol allows remote attackers to bypass
  protection mechanisms (CVE-2019-9948)
* Regression of CVE-2019-9636 due to functional fix to allow port numbers in
  netloc (CVE-2019-10160)
* email.utils.parseaddr wrongly parses email addresses (CVE-2019-16056)
* XSS vulnerability in the documentation XML-RPC server in server_title field
  (CVE-2019-16935)
* CRLF injection via the host part of the url passed to urlopen()
  (CVE-2019-18348)
* Wrong backtracking in urllib.request.AbstractBasicAuthHandler allows for a
  ReDoS (CVE-2020-8492)
* DoS via inefficiency in IPv{4,6}Interface classes (CVE-2020-14422)
Comment 1 Felix Botner univentionstaff 2020-11-19 11:23:00 CET
-> python3.5:
  Installiert:           3.5.3-1+deb9u2
  Installationskandidat: 3.5.3-1+deb9u2
  Versionstabelle:
 *** 3.5.3-1+deb9u2 500
        500 http://192.168.0.10/build2 ucs_4.3-0-extsec4.3/amd64/ Packages
Comment 2 Erik Damrose univentionstaff 2020-11-30 12:46:52 CET
CLOSED: Released as extsec4.3 update