Bug 33313 - python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043
Summary: python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2...
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Python Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-18 14:10 CEST by Nicolas Salguero
Modified: 2024-09-18 14:19 CEST (History)
1 user (show)

See Also:
Source RPM: python-2.7.18-18.mga10.src.rpm
CVE: CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043
Status comment:


Attachments

Description Nicolas Salguero 2024-06-18 14:10:03 CEST
Those CVEs were announced here:
https://www.openwall.com/lists/oss-security/2024/06/17/2
https://www.openwall.com/lists/oss-security/2024/06/17/3

For Cauldon, only python 2.7.x is affected because python 3.12.4 contains the fixes for those problems.

Mageia 9 is also affected.
Nicolas Salguero 2024-06-18 14:11:34 CEST

Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2024-0397, CVE-2024-4032
Source RPM: (none) => python3, python
Status comment: (none) => Fixed upstream in 3.12.4 and patches available from upstream

Comment 1 Marja Van Waes 2024-06-20 21:13:31 CEST
Assgining to the Python Stack Maintainers

CC: (none) => marja11
Assignee: bugsquad => python

Comment 2 Nicolas Salguero 2024-09-18 14:19:23 CEST
For python3, all is now in bug 33436 so this bug is only for python 2.7.

CVE: CVE-2024-0397, CVE-2024-4032 => CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043
Source RPM: python3, python => python-2.7.18-18.mga10.src.rpm
Summary: python3 and python new security issues CVE-2024-0397 and CVE-2024-4032 => python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043
Status comment: Fixed upstream in 3.12.4 and patches available from upstream => (none)


Note You need to log in before you can comment on or make changes to this bug.