Hi,

You are receiving an AlmaLinux Security update email because you subscribed to 
receive errata notifications from AlmaLinux.

AlmaLinux: 8
Type: Security
Severity: Moderate
Release date: 2023-05-19

Summary:

Python is an interpreted, interactive, object-oriented programming language, 
which includes modules, classes, exceptions, very high level dynamic data types 
and dynamic typing. Python supports interfaces to many system calls and 
libraries, as well as to various windowing systems.

The following packages have been upgraded to a later upstream version: python39 
(3.9.16).

Security Fix(es):

* python: int() type in PyLong_FromString() does not limit amount of digits 
converting text to int leading to DoS (CVE-2020-10735)
* python: open redirection vulnerability in lib/http/server.py may lead to 
information disclosure (CVE-2021-28861)
* python: CPU denial of service via inefficient IDNA decoder (CVE-2022-45061)

For more details about the security issue(s), including the impact, a CVSS 
score, acknowledgments, and other related information, refer to the CVE page(s) 
listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release 
Notes linked from the References section.

Full details, updated packages, references, and other related information: 
https://errata.almalinux.org/8/ALSA-2023-2764.html

This message is automatically generated, please don’t reply. For further 
questions, please, contact us via the AlmaLinux community chat: 
https://chat.almalinux.org/.
Want to change your notification settings? Sign in and manage mailing lists on 
https://lists.almalinux.org.

Kind regards,
AlmaLinux Team

Reply via email to