[CLSA-2021:1634925483] Fix of CVE: CVE-2018-20852, CVE-2020-27619, CVE-2020-26116, CVE-2020-8492
Type:
security
Severity:
moderate
Release date:
2021-10-22
Description:
- Add Oracle Linux distribution in platform.py - CVE-2018-20852: Prefix dot in domain for proper subdomain validation - CVE-2020-8492: Python allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client - CVE-2020-26116: http.client allows CRLF injection if the attacker controls the HTTP request method - CVE-2020-27619: Unsafe use of eval() on data retrieved via HTTP in the test suite
Updated packages:
  • python-devel-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:9e4f1a6166f885c8d7ed12dbac2a0a244b933ddb
  • python-tools-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:737a067b7c093df6f113268c6742195eeb5d14f4
  • tkinter-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:f599dd1c74549e263a1470d505426389bbea3dc0
  • python-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:366e2f63916b5e8337042d057d151b59a8cd1ff7
  • python-libs-2.6.6-70.el6.cloudlinux.els.i686.rpm
    sha:ccb272da75672e3bb92cc332f213747b2b1919e8
  • python-libs-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:a030527403cacbf91408ef4528ac112552648d36
  • python-2.6.6-70.el6.cloudlinux.els.i686.rpm
    sha:ce1c60046c278755e733a7f094563dd1bef4c934
  • python-devel-2.6.6-70.el6.cloudlinux.els.i686.rpm
    sha:ad5bc6ef9a5530367dee480025eacb5469b08f07
  • python-test-2.6.6-70.el6.cloudlinux.els.x86_64.rpm
    sha:c131944e1bb51dd54ea3d5a08d2132361be5eb7f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.