OESA-2021-1412
Dashboard / Vulnerabilities / OESA-2021-1412
Summary: python-psutil security update
Details: psutil (process and system utilities) is a cross-platform library for retrieving information on running processes and system utilization (CPU, memory, disks, network, sensors) in Python. It is useful mainly for system monitoring, profiling and limiting process resources and management of running processes.It implements many functionalities offered by classic UNIX command line tools such as ps, top, iotop, lsof, netstat, ifconfig, free and others. Security Fix(es): psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs because of refcount mishandling within a while or for loop that converts system data into a Python object.(CVE-2019-18874)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1412, https://nvd.nist.gov/vuln/detail/CVE-2019-18874
Affected packages
Package
Name: python-psutil
Purl: pkg:rpm/openEuler/python-psutil&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
