Bug 33313 - python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168, CVE-2025-12084
Summary: python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2...
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Python Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-06-18 14:10 CEST by Nicolas Salguero
Modified: 2025-12-08 13:36 CET (History)
1 user (show)

See Also:
Source RPM: python-2.7.18-20.mga10.src.rpm, python-2.7.18-15.2.mga9.src.rpm
CVE: CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168, CVE-2025-12084
Status comment:


Attachments

Description Nicolas Salguero 2024-06-18 14:10:03 CEST
Those CVEs were announced here:
https://www.openwall.com/lists/oss-security/2024/06/17/2
https://www.openwall.com/lists/oss-security/2024/06/17/3

For Cauldon, only python 2.7.x is affected because python 3.12.4 contains the fixes for those problems.

Mageia 9 is also affected.
Nicolas Salguero 2024-06-18 14:11:34 CEST

Source RPM: (none) => python3, python
Status comment: (none) => Fixed upstream in 3.12.4 and patches available from upstream
CVE: (none) => CVE-2024-0397, CVE-2024-4032
Whiteboard: (none) => MGA9TOO

Comment 1 Marja Van Waes 2024-06-20 21:13:31 CEST
Assgining to the Python Stack Maintainers

CC: (none) => marja11
Assignee: bugsquad => python

Comment 2 Nicolas Salguero 2024-09-18 14:19:23 CEST
For python3, all is now in bug 33436 so this bug is only for python 2.7.

Summary: python3 and python new security issues CVE-2024-0397 and CVE-2024-4032 => python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043
CVE: CVE-2024-0397, CVE-2024-4032 => CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043
Status comment: Fixed upstream in 3.12.4 and patches available from upstream => (none)
Source RPM: python3, python => python-2.7.18-18.mga10.src.rpm

Comment 3 Nicolas Salguero 2025-03-14 14:20:33 CET
openSUSE has issued an advisory on March 14:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/ADEZTCNF2JC2QQ3DY2HEUZBS6L2P2HO3/

Summary: python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043 => python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168
CVE: CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043 => CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168

Comment 4 Nicolas Salguero 2025-12-08 13:35:50 CET
Reference: https://www.openwall.com/lists/oss-security/2025/12/05/5

According to Debian, python 2.7 is only affected by CVE-2025-12084.

Summary: python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168 => python new security issues CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168, CVE-2025-12084
CVE: CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168 => CVE-2024-0397, CVE-2024-6923, CVE-2024-8088, CVE-2024-6232, CVE-2024-7592, CVE-2023-27043, CVE-2024-11168, CVE-2025-12084

Nicolas Salguero 2025-12-08 13:36:31 CET

Source RPM: python-2.7.18-18.mga10.src.rpm => python-2.7.18-20.mga10.src.rpm, python-2.7.18-15.2.mga9.src.rpm


Note You need to log in before you can comment on or make changes to this bug.