openSUSE-SU-2021:4104-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:4104-1
openSUSE-SU-2021:4104-1
Summary: Security update for python3
Details: This update for python3 fixes the following issues: - CVE-2021-3426: Fixed information disclosure via pydoc (bsc#1183374). - CVE-2021-3733: Fixed infinitely reading potential HTTP headers after a 100 Continue status response from the server (bsc#1189241). - CVE-2021-3737: Fixed ReDoS in urllib.request (bsc#1189287). - We do not require python-rpm-macros package (bsc#1180125). - Use versioned python-Sphinx to avoid dependency on other version of Python (bsc#1183858). - Stop providing 'python' symbol, which means python2 currently (bsc#1185588). - Modify Lib/ensurepip/__init__.py to contain the same version numbers as are in reality the ones in the bundled wheels (bsc#1187668).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/KYXM7YGLJSNOU4FYI3M2QXACCQ4SO3AE/, https://bugzilla.suse.com/1180125, https://bugzilla.suse.com/1183374, https://bugzilla.suse.com/1183858, https://bugzilla.suse.com/1185588, https://bugzilla.suse.com/1187668, https://bugzilla.suse.com/1189241, https://bugzilla.suse.com/1189287, https://www.suse.com/security/cve/CVE-2021-3426, https://www.suse.com/security/cve/CVE-2021-3733, https://www.suse.com/security/cve/CVE-2021-3737
Affected packages
Package
Name: python3
Purl: pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
