Release Info

Advisory: CLSA-2024:1727289133

OS: CentOS 7 ELS

Public date: 2024-09-25 14:32:16

Project: python3

Version: 3.6.8-21.el7_9.tuxcare.els4

Errata link: https://errata.tuxcare.com/els_os/centos7els/CLSA-2024-1727289133.html

Changelog

- CVE-2024-6232: remove backtracking when parsing tarfile headers - CVE-2024-7592: fix quadratic complexity in parsing "-quoted cookie values with backslashes

Update

Update command: yum update python3*

Packages list

python3-3.6.8-21.el7_9.tuxcare.els4.i686.rpm python3-3.6.8-21.el7_9.tuxcare.els4.x86_64.rpm python3-debug-3.6.8-21.el7_9.tuxcare.els4.i686.rpm python3-debug-3.6.8-21.el7_9.tuxcare.els4.x86_64.rpm python3-devel-3.6.8-21.el7_9.tuxcare.els4.i686.rpm python3-devel-3.6.8-21.el7_9.tuxcare.els4.x86_64.rpm python3-idle-3.6.8-21.el7_9.tuxcare.els4.i686.rpm python3-idle-3.6.8-21.el7_9.tuxcare.els4.x86_64.rpm python3-libs-3.6.8-21.el7_9.tuxcare.els4.i686.rpm python3-libs-3.6.8-21.el7_9.tuxcare.els4.x86_64.rpm python3-test-3.6.8-21.el7_9.tuxcare.els4.i686.rpm python3-test-3.6.8-21.el7_9.tuxcare.els4.x86_64.rpm python3-tkinter-3.6.8-21.el7_9.tuxcare.els4.i686.rpm python3-tkinter-3.6.8-21.el7_9.tuxcare.els4.x86_64.rpm

CVEs

CVE-2024-6232
CVE-2024-7592