Bug 29450

Summary: python3 new security issues fixed upstream in 3.8.12
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: QA Team <qa-bugs>
Status: RESOLVED FIXED QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: andrewsfarm, davidwhodgins, herman.viaene, jani.valimaa, sysadmin-bugs
Version: 8Keywords: advisory, validated_update
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA8-64-OK
Source RPM: python3-3.8.11-1.1.mga8.src.rpm CVE:
Status comment:

Description David Walser 2021-09-08 23:00:24 CEST
Fedora has issued an advisory today (September 8):
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/K7QDAEX4PWRYYEIXRF5QDGKJULJO6HKD/

3.8.12, released on August 30, fixed a few security issues:
https://docs.python.org/release/3.8.12/whatsnew/changelog.html
Comment 1 David Walser 2021-09-13 03:24:35 CEST
Updated package uploaded by Jani.

python3-3.8.12-1.mga8
libpython3.8-stdlib-3.8.12-1.mga8
libpython3.8-3.8.12-1.mga8
libpython3-devel-3.8.12-1.mga8
tkinter3-apps-3.8.12-1.mga8
tkinter3-3.8.12-1.mga8
libpython3.8-testsuite-3.8.12-1.mga8
python3-docs-3.8.12-1.mga8

from python3-3.8.12-1.mga8.src.rpm

Assignee: python => qa-bugs
CC: (none) => jani.valimaa

Comment 2 Herman Viaene 2021-09-13 16:16:22 CEST
MGA8-64 Plasma on Lenovo B50
No installation issues.
Ref bug 29288 for testing.
As indicated there , closed and reopened QARepo, also launched isodumper (was installed for this test), and all seems OK.

Whiteboard: (none) => MGA8-64-OK
CC: (none) => herman.viaene

Comment 3 Thomas Andrews 2021-09-14 02:41:46 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 4 David Walser 2021-09-16 22:12:46 CEST
One of the commits referenced by Ubuntu for CVE-2021-3737 is included in this update, just FYI:
https://ubuntu.com/security/notices/USN-5083-1
https://ubuntu.com/security/CVE-2021-3737
Dave Hodgins 2021-09-22 23:17:36 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 5 Mageia Robot 2021-09-23 06:52:30 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2021-0435.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED