Release Info

Advisory: CLSA-2021:1633442879

OS: CentOS 6 ELS

Public date: 2021-10-05 00:00:00

Project: python

Version: 2.6.6-70.el6.cloudlinux.els

Errata link: https://errata.cloudlinux.com/els6/CLSA-2021-1633442879.html

Changelog

- Add Oracle Linux distribution in platform.py - CVE-2018-20852: Prefix dot in domain for proper subdomain validation - CVE-2020-8492: Python allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client - CVE-2020-26116: http.client allows CRLF injection if the attacker controls the HTTP request method - CVE-2020-27619: Unsafe use of eval() on data retrieved via HTTP in the test suite

Update

Packages list

python-libs-2.6.6-70.el6.cloudlinux.els.i686.rpm python-tools-2.6.6-70.el6.cloudlinux.els.x86_64.rpm python-devel-2.6.6-70.el6.cloudlinux.els.i686.rpm python-devel-2.6.6-70.el6.cloudlinux.els.x86_64.rpm python-2.6.6-70.el6.cloudlinux.els.x86_64.rpm tkinter-2.6.6-70.el6.cloudlinux.els.x86_64.rpm python-test-2.6.6-70.el6.cloudlinux.els.x86_64.rpm python-2.6.6-70.el6.cloudlinux.els.i686.rpm python-libs-2.6.6-70.el6.cloudlinux.els.x86_64.rpm

CVEs

CVE-2020-8492
CVE-2018-20852
CVE-2020-26116
CVE-2020-27619