python-2.7.5-94.0.4.el7.AXS7

エラータID: AXSA:2024-8942:49

Release date: 
Thursday, October 24, 2024 - 16:07
Subject: 
python-2.7.5-94.0.4.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Python is an interpreted, interactive, object-oriented programming language
often compared to Tcl, Perl, Scheme or Java. Python includes modules, classes,
exceptions, very high level dynamic data types and dynamic typing. Python
supports interfaces to many system calls and libraries, as well as to various
windowing systems (X11, Motif, Tk, Mac and MFC).

Programmers can write new built-in modules for Python in C or C++. Python can be
used as an extension language for applications that need a programmable
interface.

Note that documentation for Python is provided in the python-docs package.

This package provides the "python" executable; most of the actual implementation
is within the "python-libs" package.

Security Fix(es):

* CVE-2024-7592: fix algorithm with quadratic complexity to avoid using excess
CPU resources while parsing the cookie value.

CVE(s):
CVE-2024-7592
There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

Asianux Server 7 for x86_64
  1. python-2.7.5-94.0.4.el7.AXS7.x86_64.rpm
    MD5: 9d33591191cc81b6aac88de8a5685160
    SHA-256: 8caa9170501d4776fbe579cfa5e554c93b7e9c8da20c8cbd7aba520396fe1dbe
    Size: 97.03 kB
  2. python-devel-2.7.5-94.0.4.el7.AXS7.x86_64.rpm
    MD5: 87e7878bf886446e85db615984861a7f
    SHA-256: d97c4a76ce992d902d5f2c761b4e2811f45d1435999fc0d7363fed81c2ed8a55
    Size: 399.66 kB
  3. python-libs-2.7.5-94.0.4.el7.AXS7.i686.rpm
    MD5: 56985d2d6f3500e3f638e4ddadd25c4b
    SHA-256: 75f68d23322c04519331daaff7d3ac909acc83ec7a920cdadde97cc4153ce7b5
    Size: 5.60 MB
  4. python-libs-2.7.5-94.0.4.el7.AXS7.x86_64.rpm
    MD5: bfce84414e5550b72af91c8cbb0221c9
    SHA-256: f3d3f75f8f62eafd1656d297eae94bbf302e016dd17e04e17be9aa8c5080a9f0
    Size: 5.65 MB