Univention Bugzilla – Bug 48767
python3.4: Multiple issues (4.2)
Last modified: 2019-02-27 14:06:44 CET
New Debian python3.4 3.4.2-1+deb8u2 fixes: This update addresses the following issues: * 3.4.2-1+deb8u2 (Wed, 06 Feb 2019 16:55:11 +1100) * Non-maintainer upload by the LTS Team. * CVE-2016-0772: Check for StartTLS failure. * CVE-2016-5636: Fix integer overflow in the get_data. * CVE-2016-5699: Fix CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib. * CVE-2018-20406: Fix Modules/_pickle.c integer overflow. * CVE-2019-5010: Fix NULL pointer dereference using a specially crafted X509 certificate. * 3.4.2-1+deb8u2 (Wed, 06 Feb 2019 16:55:11 +1100) * Non-maintainer upload by the LTS Team. * CVE-2016-0772: Check for StartTLS failure. * CVE-2016-5636: Fix integer overflow in the get_data. * CVE-2016-5699: Fix CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib. * CVE-2018-20406: Fix Modules/_pickle.c integer overflow. * CVE-2019-5010: Fix NULL pointer dereference using a specially crafted X509 certificate. * 3.4.2-1+deb8u2 (Wed, 06 Feb 2019 16:55:11 +1100) * Non-maintainer upload by the LTS Team. * CVE-2016-0772: Check for StartTLS failure. * CVE-2016-5636: Fix integer overflow in the get_data. * CVE-2016-5699: Fix CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib. * CVE-2018-20406: Fix Modules/_pickle.c integer overflow. * CVE-2019-5010: Fix NULL pointer dereference using a specially crafted X509 certificate. * 3.4.2-1+deb8u2 (Wed, 06 Feb 2019 16:55:11 +1100) * Non-maintainer upload by the LTS Team. * CVE-2016-0772: Check for StartTLS failure. * CVE-2016-5636: Fix integer overflow in the get_data. * CVE-2016-5699: Fix CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib. * CVE-2018-20406: Fix Modules/_pickle.c integer overflow. * CVE-2019-5010: Fix NULL pointer dereference using a specially crafted X509 certificate.
--- mirror/ftp/4.2/unmaintained/component/4.2-5-errata/source/python3.4_3.4.2-1+deb8u1.dsc +++ apt/ucs_4.2-0-errata4.2-5/source/python3.4_3.4.2-1+deb8u2.dsc @@ -1,3 +1,14 @@ +3.4.2-1+deb8u2 [Wed, 06 Feb 2019 16:55:11 +1100] Brian May <bam@debian.org>: + + * Non-maintainer upload by the LTS Team. + * CVE-2016-0772: Check for StartTLS failure. + * CVE-2016-5636: Fix integer overflow in the get_data. + * CVE-2016-5699: Fix CRLF injection vulnerability in the + HTTPConnection.putheader function in urllib2 and urllib. + * CVE-2018-20406: Fix Modules/_pickle.c integer overflow. + * CVE-2019-5010: Fix NULL pointer dereference using a specially crafted X509 + certificate. + 3.4.2-1+deb8u1 [Tue, 25 Sep 2018 15:08:31 -0400] Antoine Beaupré <anarcat@debian.org>: * Non-maintainer upload by the LTS Security Team. <http://10.200.17.11/4.2-5/#2496258489373023399>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.2-5] 93149ae3d7 Bug #48767: python3.4 3.4.2-1+deb8u2 doc/errata/staging/python3.4.yaml | 39 +++++++-------------------------------- 1 file changed, 7 insertions(+), 32 deletions(-) [4.2-5] adce3f69e8 Bug #48767: python3.4 3.4.2-1+deb8u2 doc/errata/staging/python3.4.yaml | 47 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 47 insertions(+)
<http://errata.software-univention.de/ucs/4.2/605.html>