Bug 33313

Summary: python3 and python new security issues CVE-2024-0397 and CVE-2024-4032
Product: Mageia Reporter: Nicolas Salguero <nicolas.salguero>
Component: SecurityAssignee: Python Stack Maintainers <python>
Status: NEW --- QA Contact: Sec team <security>
Severity: normal    
Priority: Normal CC: marja11
Version: Cauldron   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: MGA9TOO
Source RPM: python3, python CVE: CVE-2024-0397, CVE-2024-4032
Status comment: Fixed upstream in 3.12.4 and patches available from upstream

Description Nicolas Salguero 2024-06-18 14:10:03 CEST
Those CVEs were announced here:
https://www.openwall.com/lists/oss-security/2024/06/17/2
https://www.openwall.com/lists/oss-security/2024/06/17/3

For Cauldon, only python 2.7.x is affected because python 3.12.4 contains the fixes for those problems.

Mageia 9 is also affected.
Nicolas Salguero 2024-06-18 14:11:34 CEST

CVE: (none) => CVE-2024-0397, CVE-2024-4032
Status comment: (none) => Fixed upstream in 3.12.4 and patches available from upstream
Source RPM: (none) => python3, python
Whiteboard: (none) => MGA9TOO

Comment 1 Marja Van Waes 2024-06-20 21:13:31 CEST
Assgining to the Python Stack Maintainers

Assignee: bugsquad => python
CC: (none) => marja11