openSUSE-SU-2022:1091-1
Dashboard / Vulnerabilities / openSUSE-SU-2022:1091-1
openSUSE-SU-2022:1091-1
Summary: Security update for python
Details: This update for python fixes the following issues: - CVE-2022-0391: Fixed URL sanitization containing ASCII newline and tabs in urlparse (bsc#1195396). - CVE-2021-4189: Fixed ftplib not to trust the PASV response (bsc#1194146). - CVE-2021-3572: Fixed an improper handling of unicode characters in pip (bsc#1186819).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/ULIK4RFHGHTVVWROQ6NTBBB4JWOGWYD6/, https://bugzilla.suse.com/1175619, https://bugzilla.suse.com/1186819, https://bugzilla.suse.com/1194146, https://bugzilla.suse.com/1195396, https://www.suse.com/security/cve/CVE-2021-3572, https://www.suse.com/security/cve/CVE-2021-4189, https://www.suse.com/security/cve/CVE-2022-0391
Affected packages
Package
Name: python
Purl: pkg:rpm/opensuse/python&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
