SUSE-SU-2022:1140-1
Dashboard / Vulnerabilities / SUSE-SU-2022:1140-1
SUSE-SU-2022:1140-1
Summary: Security update for python
Details: This update for python rebuilds python against a symbol versioned openssl 1.0.2 to allow usage with openssl 1.1.1. Also the following security issues are fixed: - CVE-2022-0391: Fixed sanitizing URLs containing ASCII newline and tabs in urlparse (bsc#1195396). - CVE-2021-4189: Make ftplib not trust the PASV response (bsc#1194146).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20221140-1/, https://bugzilla.suse.com/1187784, https://bugzilla.suse.com/1194146, https://bugzilla.suse.com/1195396, https://www.suse.com/security/cve/CVE-2021-4189, https://www.suse.com/security/cve/CVE-2022-0391
Affected packages
Package
Name: python
Purl: pkg:rpm/suse/python&distro=SUSE%20OpenStack%20Cloud%209
Affected ranges
Type: ECOSYSTEM
Events:
