SUSE-SU-2016:2653-1
Dashboard / Vulnerabilities / SUSE-SU-2016:2653-1
SUSE-SU-2016:2653-1
Summary: Security update for python3
Details: This update provides Python 3.4.5, which brings many fixes and enhancements. The following security issues have been fixed: - CVE-2016-1000110: CGIHandler could have allowed setting of HTTP_PROXY environment variable based on user supplied Proxy request header. (bsc#989523) - CVE-2016-0772: A vulnerability in smtplib could have allowed a MITM attacker to perform a startTLS stripping attack. (bsc#984751) - CVE-2016-5636: A heap overflow in Python's zipimport module. (bsc#985177) - CVE-2016-5699: A header injection flaw in urrlib2/urllib/httplib/http.client. (bsc#985348) The update also includes the following non-security fixes: - Don't force 3rd party C extensions to be built with -Werror=declaration-after-statement. (bsc#951166) - Make urllib proxy var handling behave as usual on POSIX. (bsc#983582) For a comprehensive list of changes please refer to the upstream change log: https://docs.python.org/3.4/whatsnew/changelog.html
References: https://www.suse.com/support/update/announcement/2016/suse-su-20162653-1/, https://bugzilla.suse.com/951166, https://bugzilla.suse.com/983582, https://bugzilla.suse.com/984751, https://bugzilla.suse.com/985177, https://bugzilla.suse.com/985348, https://bugzilla.suse.com/989523, https://bugzilla.suse.com/991069, https://www.suse.com/security/cve/CVE-2016-0772, https://www.suse.com/security/cve/CVE-2016-1000110, https://www.suse.com/security/cve/CVE-2016-5636, https://www.suse.com/security/cve/CVE-2016-5699
Affected packages
Package
Name: python3
Purl: pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
