update: python #1402
Labels
advisory/only-sdk
affects only Flatcar SDK
advisory
security advisory
cvss/HIGH
> 7 && < 9 assessed CVSS
security
security concerns
Name: python
CVEs: CVE-2023-6597, CVE-2024-0450, gh-81194, gh-102388, gh-113659, gh-114572, gh-115243
CVSSs: 7.8, 6.2, n/a, n/a, n/a, n/a, n/a
Action Needed: update to >= 3.12.3, 3.11.9
Summary:
tempfile.TemporaryDirectory
class affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior. The tempfile.TemporaryDirectory class would dereference symlinks during cleanup of permissions-related errors. This means users which can run privileged programs are potentially able to modify permissions of files referenced by symlinks in some circumstances.zipfile
module affecting versions 3.12.2, 3.11.8, 3.10.13, 3.9.18, and 3.8.18 and prior. The zipfile module is vulnerable to “quoted-overlap” zip-bombs which exploit the zip format to create a zip-bomb with a high compression ratio. The fixed versions of CPython makes the zipfile module reject zip archives which overlap entries in the archive.See also https://discuss.python.org/t/python-3-10-14-3-9-19-and-3-8-19-is-now-available/48993.
refmap.gentoo:
The text was updated successfully, but these errors were encountered: