SUSE-SU-2016:2270-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2270-1
SUSE-SU-2016:2270-1
Summary: Security update for python
Details: This update for python fixes the following issues: - CVE-2016-0772: smtplib vulnerability opens startTLS stripping attack (bsc#984751) - CVE-2016-5699: incorrect validation of HTTP headers allow header injection (bsc#985348) - CVE-2016-1000110: HTTPoxy vulnerability in urllib, fixed by disregarding HTTP_PROXY when REQUEST_METHOD is also set (bsc#989523)
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162270-1/, https://bugzilla.suse.com/984751, https://bugzilla.suse.com/985348, https://bugzilla.suse.com/989523, https://www.suse.com/security/cve/CVE-2016-0772, https://www.suse.com/security/cve/CVE-2016-1000110, https://www.suse.com/security/cve/CVE-2016-5699
Affected packages
Package
Name: python
Purl: pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
