Uploaded image for project: 'Funtoo Linux'
  1. Funtoo Linux
  2. FL-9816

dev-lang/python:3.7 CVE-2021-3737 CVE-2022-0391

    • Icon: Security Vulnerability Security Vulnerability
    • Resolution: Fixed
    • Icon: Normal Normal
    • None
    • None

      In the python version we have in the stable tree we have 2 cve which we can patch by boosting the package to the current minor version.

      {
         "id":"CVE-2021-3737",
         "is_known_exploited_vuln":false,
         "description":"A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.",
         "urls":[
            "https://nvd.nist.gov/vuln/detail/CVE-2021-3737",
            "https://github.com/python/cpython/pull/25916",
            "https://bugzilla.redhat.com/show_bug.cgi?id=1995162",
            "https://ubuntu.com/security/CVE-2021-3737",
            "https://github.com/python/cpython/pull/26503",
            "https://bugs.python.org/issue44022",
            "https://python-security.readthedocs.io/vuln/urllib-100-continue-loop.html",
            "https://security.netapp.com/advisory/ntap-20220407-0009/"
         ]
      }{
         "id":"CVE-2022-0391",
         "is_known_exploited_vuln":false,
         "description":"A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\\r' and '\\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.",
         "urls":[
            "https://nvd.nist.gov/vuln/detail/CVE-2022-0391",
            "https://bugs.python.org/issue43882",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CSD2YBXP3ZF44E44QMIIAR5VTO35KTRB/",
            "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDBDBAU6HUPZHISBOARTXZ5GKHF2VH5U/",
            "https://security.netapp.com/advisory/ntap-20220225-0009/",
            "https://www.oracle.com/security-alerts/cpuapr2022.html"
         ]
      }
      

      Other identified CVEs are yet to be fixed in higher versions of Python.

      From my python perspective, slot 3.7 should be autogen

            drobbins drobbins
            tczaude tczaude
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: