Bug 31052 - Update request: python3 3.8.15
Summary: Update request: python3 3.8.15
Status: RESOLVED DUPLICATE of bug 31000
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL: https://www.python.org/downloads/rele...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-10-30 15:31 CET by Jani Välimaa
Modified: 2022-10-31 15:55 CET (History)
0 users

See Also:
Source RPM: python3-3.8.14-1.1.mga8
CVE:
Status comment:


Attachments

Description Jani Välimaa 2022-10-30 15:31:25 CET
According to upstream new python3 3.8.15 fixes security issues:

Security content in this release
- CVE-2022-40674: bundled libexpat was upgraded from 2.4.7 to 2.4.9 which fixes a heap use-after-free vulnerability in function doContent
- gh-97616: a fix for a possible buffer overflow in list *= int
- gh-97612: a fix for possible shell injection in the example script get-remote certificate.py (this issue originally had a CVE assigned to it, which its author withdrew)
- gh-96577: a fix for a potential buffer overrun in msilib

We don't use bundled libexpat.
Comment 1 Jani Välimaa 2022-10-30 16:57:37 CET
Please test pkgs from mga8 core/updates_testing.

SRPMS:
python3-3.8.15-1.mga8

RPMS:
python3-3.8.15-1.mga8
lib(64)python3.8-3.8.15-1.mga8
lib(64)python3.8-stdlib-3.8.15-1.mga8
lib(64)python3.8-testsuite-3.8.15-1.mga8
lib(64)python3-devel-3.8.15-1.mga8
python3-docs-3.8.15-1.mga8
tkinter3-3.8.15-1.mga8
tkinter3-apps-3.8.15-1.mga8

Assignee: jani.valimaa => qa-bugs
URL: (none) => https://www.python.org/downloads/release/python-3815/

Comment 2 David Walser 2022-10-31 15:55:27 CET
Please be on the lookout for bugs I file :o)

*** This bug has been marked as a duplicate of bug 31000 ***

Resolution: (none) => DUPLICATE
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.