ALSA-2024:8834
Dashboard / Vulnerabilities / ALSA-2024:8834
Summary: Important: python-gevent security update
Details: gevent is a coroutine-based Python networking library that uses greenlet to provide a high-level synchronous API on top of libevent event loop. Features include: * convenient API around greenlets * familiar synchronization primitives (gevent.event, gevent.queue) * socket module that cooperates * WSGI server on top of libevent-http * DNS requests done through libevent-dns * monkey patching utility to get pure Python modules to cooperate Security Fix(es): * python-gevent: privilege escalation via a crafted script to the WSGIServer component (CVE-2023-41419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://access.redhat.com/errata/RHSA-2024:8834, https://access.redhat.com/security/cve/CVE-2023-41419, https://bugzilla.redhat.com/2240651, https://errata.almalinux.org/8/ALSA-2024-8834.html
Affected packages
Package
Name: python3-gevent
Purl: pkg:rpm/almalinux/python3-gevent
Affected ranges
Type: ECOSYSTEM
Events:
