[ubuntu/focal-updates] python3.8 3.8.10-0ubuntu1~20.04.12 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Mon Sep 16 13:29:25 UTC 2024
python3.8 (3.8.10-0ubuntu1~20.04.12) focal-security; urgency=medium
* SECURITY UPDATE: incorrect special character parsing in email module
- debian/patches/CVE-2023-27043.patch: reject malformed addresses in
Doc/library/email.utils.rst, Lib/email/utils.py,
Lib/test/test_email/test_email.py.
- CVE-2023-27043
* SECURITY UPDATE: ReDoS via specifically-crafted tar archives
- debian/patches/CVE-2024-6232.patch: remove backtracking when parsing
tarfile headers in Lib/tarfile.py, Lib/test/test_tarfile.py.
- CVE-2024-6232
* SECURITY UPDATE: header injection via newlines in email module
- debian/patches/CVE-2024-6923.patch: encode newlines in headers, and
verify headers are sound in Doc/library/email.errors.rst,
Doc/library/email.policy.rst, Lib/email/_header_value_parser.py,
Lib/email/_policybase.py, Lib/email/errors.py,
Lib/email/generator.py, Lib/test/test_email/test_generator.py,
Lib/test/test_email/test_policy.py.
- CVE-2024-6923
* SECURITY UPDATE: resource consumption via cookie parsing
- debian/patches/CVE-2024-7592.patch: fix quadratic complexity in
parsing quoted cookie values with backslashes in Lib/http/cookies.py,
Lib/test/test_http_cookies.py.
- CVE-2024-7592
* SECURITY UPDATE: infinite loop via crafted zip archive
- debian/patches/CVE-2024-8088.patch: sanitize names in zipfile.Path in
Lib/test/test_zipfile/_path/test_path.py,
Lib/zipfile/_path/__init__.py.
- CVE-2024-8088
Date: 2024-09-12 11:27:11.508971+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.12
-------------- next part --------------
Sorry, changesfile not available.
More information about the Focal-changes
mailing list