SUSE-SU-2021:4104-1
Dashboard / Vulnerabilities / SUSE-SU-2021:4104-1
SUSE-SU-2021:4104-1
Summary: Security update for python3
Details: This update for python3 fixes the following issues: - CVE-2021-3426: Fixed information disclosure via pydoc (bsc#1183374). - CVE-2021-3733: Fixed infinitely reading potential HTTP headers after a 100 Continue status response from the server (bsc#1189241). - CVE-2021-3737: Fixed ReDoS in urllib.request (bsc#1189287). - We do not require python-rpm-macros package (bsc#1180125). - Use versioned python-Sphinx to avoid dependency on other version of Python (bsc#1183858). - Stop providing 'python' symbol, which means python2 currently (bsc#1185588). - Modify Lib/ensurepip/__init__.py to contain the same version numbers as are in reality the ones in the bundled wheels (bsc#1187668).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20214104-1/, https://bugzilla.suse.com/1180125, https://bugzilla.suse.com/1183374, https://bugzilla.suse.com/1183858, https://bugzilla.suse.com/1185588, https://bugzilla.suse.com/1187668, https://bugzilla.suse.com/1189241, https://bugzilla.suse.com/1189287, https://www.suse.com/security/cve/CVE-2021-3426, https://www.suse.com/security/cve/CVE-2021-3733, https://www.suse.com/security/cve/CVE-2021-3737
Affected packages
Package
Name: python3
Purl: pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
