Bug 30043 - python new security issues CVE-2021-4189 and CVE-2022-0391
Summary: python new security issues CVE-2021-4189 and CVE-2022-0391
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: Python Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on: 30572 31000
Blocks:
  Show dependency treegraph
 
Reported: 2022-02-13 18:37 CET by David Walser
Modified: 2024-01-12 09:38 CET (History)
2 users (show)

See Also:
Source RPM: python-2.7.18-7.3.mga8.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2022-02-13 18:37:39 CET
Debian-LTS has issued an advisory on February 12:
https://www.debian.org/lts/security/2022/dla-2919

Mageia 8 is also affected.

Python3 was fixed in 3.8.9 (Bug 28729).
David Walser 2022-02-13 18:37:52 CET

Whiteboard: (none) => MGA8TOO
Status comment: (none) => Patch available from Debian

Comment 1 Lewis Smith 2022-02-13 21:26:50 CET
Assigning as the SRPM suggests.

Assignee: bugsquad => python

Comment 2 David Walser 2022-02-25 16:27:35 CET
Fedora has issued an advisory on February 24:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/

It fixes a new CVE (fixed in python3 in Bug 29288).

Status comment: Patch available from Debian => Patches available from Fedora and Debian
Summary: python new security issue CVE-2021-4189 => python new security issues CVE-2021-4189 and CVE-2022-0391
Severity: normal => major

Comment 3 David Walser 2022-04-04 22:39:53 CEST
openSUSE has issued an advisory for this on April 1:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULIK4RFHGHTVVWROQ6NTBBB4JWOGWYD6/

Hopefully we don't also have a bundled pip, otherwise CVE-2021-3572 would also be an issue.
Comment 4 Nicolas Lécureuil 2022-09-06 00:36:56 CEST
patches just pushed in cauldron

Version: Cauldron => 8
CC: (none) => mageia
Whiteboard: MGA8TOO => (none)

Comment 5 Nicolas Lécureuil 2022-09-06 00:39:17 CEST
fixed in mga8

src:
    - python-2.7.18-7.4.mga8

Status comment: Patches available from Fedora and Debian => (none)
Assignee: python => qa-bugs

Jani Välimaa 2022-10-04 10:05:57 CEST

Depends on: (none) => 30572

David Walser 2023-05-18 17:58:16 CEST

Depends on: (none) => 31000

Comment 7 Nicolas Salguero 2024-01-12 09:38:04 CET
Mageia 8 EOL

CC: (none) => nicolas.salguero
Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.