Univention Bugzilla – Bug 51899
python2.7: Multiple issues (4.4)
Last modified: 2020-08-26 16:35:42 CEST
New Debian python2.7 2.7.13-2+deb9u4 fixes: This update addresses the following issues: * Cookie domain check returns incorrect results (CVE-2018-20852) * NULL pointer dereference using a specially crafted X509 certificate (CVE-2019-5010) * Information Disclosure due to urlsplit improper NFKC normalization (CVE-2019-9636) * improper neutralization of CRLF sequences in urllib module (CVE-2019-9740) * improper neutralization of CRLF sequences in urllib module (CVE-2019-9947) * undocumented local_file protocol allows remote attackers to bypass protection mechanisms (CVE-2019-9948) * email.utils.parseaddr wrongly parses email addresses (CVE-2019-16056) * infinite loop in the tarfile module via crafted TAR archive (CVE-2019-20907)
--- mirror/ftp/4.3/unmaintained/4.3-3/source/python2.7_2.7.13-2+deb9u3.dsc +++ apt/ucs_4.4-0-errata4.4-5/source/python2.7_2.7.13-2+deb9u4.dsc @@ -1,3 +1,24 @@ +2.7.13-2+deb9u4 [Sat, 22 Aug 2020 12:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>: + + * Non-maintainer upload by the LTS Team. + * CVE-2019-20907 + fix for an infinite loop when opening a crafted tar file + * CVE-2019-16056 + Fix incorrect parsing of email addresses with multiple '@' characters. + * CVE-2019-10160 + Fixes regression in fix for CVE-2019-9636 + * CVE-2019-9948 + Stop urllib exposing the local_file schema (file://). + * CVE-2019-9740, CVE-2019-9947 + Disallow control chars in http URLS in urllib2.urlopen. + * CVE-2019-9636 + Fix mishandling of NFKC normalization in urlsplit + * CVE-2019-5010 + Fix NULL pointer dereference when using a specially crafted + X509 certificate + * CVE-2018-20852 + Cookie handling could be tricked to steal cookies for other domains. + 2.7.13-2+deb9u3 [Wed, 26 Sep 2018 20:42:22 +0200] Moritz Mühlenhoff <jmm@debian.org>: * CVE-2018-1000802, CVE-2018-1060, CVE-2018-1061, CVE-2018-14647 <http://10.200.17.11/4.4-5/#6102485430687758822>
OK: yaml OK: announce_errata OK: patch ~OK: piuparts Ignore purge error: > /usr/lib/python2.7/lib-dynload/ owned by: libpython2.7-minimal:amd64 [4.4-5] 9777f8877c Bug #51899: python2.7 2.7.13-2+deb9u4 doc/errata/staging/python2.7.yaml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) [4.4-5] bfb6760f22 Bug #51899: python2.7 2.7.13-2+deb9u4 doc/errata/staging/python2.7.yaml | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x718>