Bug 33313 - python3 and python new security issues CVE-2024-0397 and CVE-2024-4032
Summary: python3 and python new security issues CVE-2024-0397 and CVE-2024-4032
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Python Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-18 14:10 CEST by Nicolas Salguero
Modified: 2024-06-20 21:13 CEST (History)
1 user (show)

See Also:
Source RPM: python3, python
CVE: CVE-2024-0397, CVE-2024-4032
Status comment: Fixed upstream in 3.12.4 and patches available from upstream


Attachments

Description Nicolas Salguero 2024-06-18 14:10:03 CEST
Those CVEs were announced here:
https://www.openwall.com/lists/oss-security/2024/06/17/2
https://www.openwall.com/lists/oss-security/2024/06/17/3

For Cauldon, only python 2.7.x is affected because python 3.12.4 contains the fixes for those problems.

Mageia 9 is also affected.
Nicolas Salguero 2024-06-18 14:11:34 CEST

CVE: (none) => CVE-2024-0397, CVE-2024-4032
Status comment: (none) => Fixed upstream in 3.12.4 and patches available from upstream
Source RPM: (none) => python3, python
Whiteboard: (none) => MGA9TOO

Comment 1 Marja Van Waes 2024-06-20 21:13:31 CEST
Assgining to the Python Stack Maintainers

Assignee: bugsquad => python
CC: (none) => marja11


Note You need to log in before you can comment on or make changes to this bug.