Release Info

Advisory: CLSA-2024:1727895277

OS: Ubuntu 18.04 ELS

Public date: 2024-10-02 14:54:39

Project: python2.7

Version: 2.7.17-1~18.04ubuntu1.11+tuxcare.els9

Errata link: https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2024-1727895277.html

Changelog

* SECURITY UPDATE: Excessive CPU resources usage while parsing cookies with backslashes in value - debian/patches/CVE-2024-7592.patch: Fix quadratic complexity in parsing cookie values with backslashes - CVE-2024-7592 * SECURITY UPDATE: Regular expressions that allowed excessive backtracking during tarfile header parsing - debian/patches/CVE-2024-6232.patch: Fix regexp handling in tarfile - CVE-2024-6232 * Replace PROTOCOL_TLSv1 with PROTOCOL_TLSv1_2 in Lib/test/test_ssl.py to fix the check phase on the build system

Update

Update command: apt-get update apt-get --only-upgrade install python2.7*

Packages list

idle-python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_all.deb libpython2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_amd64.deb libpython2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_amd64.deb libpython2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_amd64.deb libpython2.7-stdlib_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_amd64.deb libpython2.7-testsuite_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_all.deb python2.7_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_amd64.deb python2.7-dev_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_amd64.deb python2.7-doc_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_all.deb python2.7-examples_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_all.deb python2.7-minimal_2.7.17-1~18.04ubuntu1.11+tuxcare.els9_amd64.deb

CVEs

CVE-2024-6232
CVE-2024-7592