[CLSA-2021:1632401716] Fix of CVE: CVE-2018-20852, CVE-2020-8492, CVE-2020-26116, CVE-2020-27619
Type:
security
Severity:
moderate
Release date:
2021-09-23
Description:
- Add Oracle Linux distribution in platform.py - CVE-2018-20852: Prefix dot in domain for proper subdomain validation - CVE-2020-8492: Python allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client - CVE-2020-26116: http.client allows CRLF injection if the attacker controls the HTTP request method - CVE-2020-27619: Unsafe use of eval() on data retrieved via HTTP in the test suite
Updated packages:
  • python-libs-2.6.6-70.el6.cloudlinux.els.i686.rpm
    sha:35d78dc89054d3d943b70b20f810deabb0593f60
  • python-tools-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:5ed4f4aad0100293c260257885f55832524803dc
  • python-devel-2.6.6-70.el6.cloudlinux.els.i686.rpm
    sha:3a142d5fefb673115a0d75478ebebdf550979baa
  • python-devel-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:a15c5e237976892df90d77d499d362fde800bd83
  • python-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:74f9cbb0497812167dac31e9a5efc0e676bc369c
  • tkinter-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:4f01388110af0be707591304893a8476dc651aa8
  • python-test-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:0be422a4d7d024e5cad1212aede8012f0276732c
  • python-2.6.6-70.el6.cloudlinux.els.i686.rpm
    sha:62cde96bba571f7626b00bce5bdcdc24c40a0110
  • python-libs-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:53a07dbe94780454a075523e7a2970a31fac177e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.