Release Info

Advisory: CLSA-2023:1689885005

OS: CentOS 8.4 ELS

Public date: 2023-07-20 16:30:07

Project: python2

Version: 2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6

Errata link: https://errata.cloudlinux.com/centos8.4-els/CLSA-2023-1689885005.html

Changelog

- CVE-2023-24329: part2: Start stripping C0 control and space chars in `urlsplit` - Also correct the first CVE-2023-24329 patch: Fix test_attributes_bad_scheme to check for non-ascii symbol as first character of url

Update

Update command: dnf update python2*

Packages list

python2-2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6.x86_64.rpm python2-debug-2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6.x86_64.rpm python2-devel-2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6.x86_64.rpm python2-libs-2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6.x86_64.rpm python2-test-2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6.x86_64.rpm python2-tkinter-2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6.x86_64.rpm python2-tools-2.7.18-4.module_el8.4.0+2123+87f40991.tuxcare.els6.x86_64.rpm

CVEs

CVE-2023-24329