CVE-2019-9948
published 2019-03-23CVE-2019-9948: urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist…
PriorityP359critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
12.26%
95.7th percentile
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | python2.7 | < python2.7 2.7.16-2 (bullseye) | python2.7 2.7.16-2 (bullseye) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| python | python | >= 2.0 < 2.7.17 | 2.7.17 |
| python | python | >= 3.5.0 < 3.5.8 | 3.5.8 |
| python | python | >= 3.6.0 < 3.6.9 | 3.6.9 |
| python | python | >= 3.7.0 < 3.7.4 | 3.7.4 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_eus | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
vendor_ubuntu7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
osv·2024-07-11·CVSS 7.6
CVE-2015-20107 [HIGH] python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
python3.5, python3.6, python3.7, python3.8, python3.9, python3.10, python3.11, python3.12 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 L
GHSA
GHSA-24p8-x4mp-cq86: urllib in Python 2
ghsa_unreviewed·2022-05-24
CVE-2019-9948 [CRITICAL] CWE-22 GHSA-24p8-x4mp-cq86: urllib in Python 2
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
OSV
python2.7, python3.4 vulnerabilities
osv·2019-09-10·CVSS 7.5
CVE-2018-20406 [HIGH] python2.7, python3.4 vulnerabilities
python2.7, python3.4 vulnerabilities
USN-4127-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 14.04 ESM. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain
OSV
python2.7, python3.5, python3.6, python3.7 vulnerabilities
osv·2019-09-09·CVSS 7.5
CVE-2018-20406 [HIGH] python2.7, python3.5, python3.6, python3.7 vulnerabilities
python2.7, python3.5, python3.6, python3.7 vulnerabilities
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2019-9636,
CVE-2019-10160)
Colin Read and Nicolas Edet discovered that Python incorrectly handled
OSV
CVE-2019-9948: urllib in Python 2
osv·2019-03-23·CVSS 9.1
CVE-2019-9948 [CRITICAL] CVE-2019-9948: urllib in Python 2
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-07-11·CVSS 7.6
CVE-2021-29921 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 18.04 LTS.
(CVE-2015-20107)
It was discovered that Python incorrectly used regular expressions
vulnerable to catastrophic backtracking. A remote attacker could possibly
use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-1060, CVE-2018-1061)
It was discovered that Python failed to initialize Expat’s hash salt. A
remote attacker could possibly use this issue to cause hash collisions,
leading to a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2018-14647)
Ubuntu
Python vulnerabilities
vendor_ubuntu·2019-09-10·CVSS 7.5
CVE-2018-20406 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
USN-4127-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 14.04 ESM. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An
Ubuntu
Python vulnerabilities
vendor_ubuntu·2019-09-09·CVSS 7.5
CVE-2018-20406 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled certain pickle files. An
attacker could possibly use this issue to consume memory, leading to a
denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2018-20406)
It was discovered that Python incorrectly validated the domain when
handling cookies. An attacker could possibly trick Python into sending
cookies to the wrong domain. (CVE-2018-20852)
Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly
handled Unicode encoding during NFKC normalization. An attacker could
possibly use this issue to obtain sensitive information. (CVE-2019-9636,
CVE-2019-10160)
Colin Read and Nicolas Edet discovered that
Red Hat
python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms
vendor_redhat·2019-03-23·CVSS 9.1
CVE-2019-9948 [CRITICAL] CWE-749 python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms
python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
Mitigation: If your application uses a blacklist to prevent "file://" schema from being used, consider using a whitelist approach to just allow the schemas you want or add "local_file://" schema to your blacklist.
Package: python (Red Hat Enterprise Linux 5) - Will not fix
Package: python (Red Hat Enterprise Linux 6) - Will not fix
Package: python3 (Red Hat Enterprise Linux 7) - Not affected
Package: python36:3.6/python36 (Red Hat Enterprise
Debian
CVE-2019-9948: python2.7 - urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes...
vendor_debian·2019·CVSS 9.1
CVE-2019-9948 [CRITICAL] CVE-2019-9948: python2.7 - urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes...
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.
Scope: local
bullseye: resolved (fixed in 2.7.16-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-9948 python3: python: undocumented local_file protocol allows remote attackers to bypass protection mechanisms [fedora-all]
bugzilla·2019-04-17·CVSS 9.1
CVE-2019-9948 [CRITICAL] CVE-2019-9948 python3: python: undocumented local_file protocol allows remote attackers to bypass protection mechanisms [fedora-all]
CVE-2019-9948 python3: python: undocumented local_file protocol allows remote attackers to bypass protection mechanisms [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2019-9948 python3: python: undocumented local_file protocol allows remote attackers to bypass protection mechanisms [fedora-all]
bugzilla·2019-04-17·CVSS 9.1
CVE-2019-9948 [CRITICAL] CVE-2019-9948 python3: python: undocumented local_file protocol allows remote attackers to bypass protection mechanisms [fedora-all]
CVE-2019-9948 python3: python: undocumented local_file protocol allows remote attackers to bypass protection mechanisms [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2019-9947 python3: python: improper neutralization of CRLF sequences in urllib module [fedora-all]
bugzilla·2019-04-11·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 python3: python: improper neutralization of CRLF sequences in urllib module [fedora-all]
CVE-2019-9947 python3: python: improper neutralization of CRLF sequences in urllib module [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2019-9947 CVE-2019-9948 python37: various flaws [fedora-28]
bugzilla·2019-04-11·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python37: various flaws [fedora-28]
CVE-2019-9947 CVE-2019-9948 python37: various flaws [fedora-28]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-28.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-9947 CVE-2019-9948 python34: various flaws [epel-all]
bugzilla·2019-04-11·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python34: various flaws [epel-all]
CVE-2019-9947 CVE-2019-9948 python34: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora EPEL.
Bugzilla
CVE-2019-9947 CVE-2019-9948 python36: various flaws [fedora-29]
bugzilla·2019-04-11·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python36: various flaws [fedora-29]
CVE-2019-9947 CVE-2019-9948 python36: various flaws [fedora-29]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-29.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update'
Bugzilla
CVE-2019-9947 CVE-2019-9948 python35: various flaws [fedora-all]
bugzilla·2019-04-11·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python35: various flaws [fedora-all]
CVE-2019-9947 CVE-2019-9948 python35: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2019-9947 CVE-2019-9948 python36: various flaws [epel-7]
bugzilla·2019-04-11·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python36: various flaws [epel-7]
CVE-2019-9947 CVE-2019-9948 python36: various flaws [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to for the 'fedpkg update' reques
Bugzilla
CVE-2019-9947 CVE-2019-9948 python34: various flaws [fedora-all]
bugzilla·2019-04-11·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python34: various flaws [fedora-all]
CVE-2019-9947 CVE-2019-9948 python34: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2019-9947 CVE-2019-9948 python3-urllib3: various flaws [epel-all]
bugzilla·2019-04-03·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python3-urllib3: various flaws [epel-all]
CVE-2019-9947 CVE-2019-9948 python3-urllib3: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
Bugzilla
CVE-2019-9947 CVE-2019-9948 python-urllib3: various flaws [fedora-all]
bugzilla·2019-04-03·CVSS 6.1
CVE-2019-9947 [MEDIUM] CVE-2019-9947 CVE-2019-9948 python-urllib3: various flaws [fedora-all]
CVE-2019-9947 CVE-2019-9948 python-urllib3: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fed
Bugzilla
CVE-2019-9948 python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms
bugzilla·2019-04-03·CVSS 9.1
CVE-2019-9948 [CRITICAL] CVE-2019-9948 python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms
CVE-2019-9948 python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes
it easier for remote attackers to bypass protection mechanisms that blacklist
file: URIs, as demonstrated by triggering a
urllib.urlopen('local_file:///etc/passwd') call.
Reference:
https://bugs.python.org/issue35907
https://github.com/python/cpython/pull/11842
Discussion:
Created python-urllib3 tracking bugs for this issue:
Affects: fedora-all [bug 1695599]
---
Created python3-urllib3 tracking bugs for this issue:
Affects: epel-all [bug 1695600]
---
Created python3 tracking bugs for this issue:
Affects: fedora-all [bug 1698976]
Created python34 tracking bugs for this issue:
Affects: fed
arXiv
Vulnerability Analysis of 2500 Docker Hub Images
arxiv_fulltext·2020-06-11
Vulnerability Analysis of 2500 Docker Hub Images
Vulnerability Analysis of 2500 Docker Hub Images
Katrine Wist
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
Malene Helsem
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
Danilo Gligoroski
Dep. of Inf. Sec. and Comm. Techn.
Norwegian University of Science
and Technology (NTNU), Norway
[email protected]
## Abstract
The use of container technology has skyrocketed during the last few years, with Docker as the leading container platform. Docker's online repository for publicly available container images, called Docker Hub, hosts over 3.5 million images at the time of writing, making it the world's largest community of container images. We pe
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.htmlhttp://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.htmlhttp://www.securityfocus.com/bid/107549https://access.redhat.com/errata/RHSA-2019:1700https://access.redhat.com/errata/RHSA-2019:2030https://access.redhat.com/errata/RHSA-2019:3335https://access.redhat.com/errata/RHSA-2019:3520https://bugs.python.org/issue35907https://github.com/python/cpython/pull/11842https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/06/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/https://seclists.org/bugtraq/2019/Oct/29https://security.gentoo.org/glsa/202003-26https://security.netapp.com/advisory/ntap-20190404-0004/https://usn.ubuntu.com/4127-1/https://usn.ubuntu.com/4127-2/http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00092.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00050.htmlhttp://packetstormsecurity.com/files/154927/Slackware-Security-Advisory-python-Updates.htmlhttp://www.securityfocus.com/bid/107549https://access.redhat.com/errata/RHSA-2019:1700https://access.redhat.com/errata/RHSA-2019:2030https://access.redhat.com/errata/RHSA-2019:3335https://access.redhat.com/errata/RHSA-2019:3520https://bugs.python.org/issue35907https://github.com/python/cpython/pull/11842https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2019/06/msg00022.htmlhttps://lists.debian.org/debian-lts-announce/2019/07/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/08/msg00034.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HQEQLXLOCR3SNM3AA5RRYJFQ5AZBYJ4L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KRYFIMISZ47NTAU3XWZUOFB7CYL62KES/https://seclists.org/bugtraq/2019/Oct/29https://security.gentoo.org/glsa/202003-26https://security.netapp.com/advisory/ntap-20190404-0004/https://usn.ubuntu.com/4127-1/https://usn.ubuntu.com/4127-2/
2019-03-23
Published