python3.12-3.12.1-4.el9_4.4

エラータID: AXSA:2024-8949:08

Release date: 
Monday, October 28, 2024 - 16:08
Subject: 
python3.12-3.12.1-4.el9_4.4
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

Python 3.12 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.12 package provides the "python3.12" executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.12-libs package, which should be installed automatically along with python3.12. The remaining parts of the Python standard library are broken out into the python3.12-tkinter and python3.12-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.12-docs package. Packages containing additional libraries for Python are generally named with the "python3.12-" prefix.

Security Fix(es):

* python: cpython: tarfile: ReDos via excessive backtracking while parsing header values (CVE-2024-6232)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-6232
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python3.12-3.12.1-4.el9_4.4.src.rpm
    MD5: 927c02aafe373b528b604709ecd98b0a
    SHA-256: c01f6b528a9bcb611795bc41db9b84c758444cbd2f3b932b49fea88a0eb7d6dd
    Size: 19.70 MB

Asianux Server 9 for x86_64
  1. python3.12-3.12.1-4.el9_4.4.i686.rpm
    MD5: d8a060463f605a688f78e3d4c4490f36
    SHA-256: 4271426cbf04530e83d68ac04c107298a64f27cc189a69732f06cbf8c9913f1c
    Size: 25.71 kB
  2. python3.12-3.12.1-4.el9_4.4.x86_64.rpm
    MD5: b81bb1b22b126325639fbd7362afa961
    SHA-256: e4c394a7e746db51d9e940d000caf62f5f393402b950554a03cea71d64770b9f
    Size: 25.62 kB
  3. python3.12-debug-3.12.1-4.el9_4.4.i686.rpm
    MD5: 36e57ffbe6fc0c39558fdd1230e0b530
    SHA-256: c8a68bf32e3433ab458ba8a92d575da19c93d1cdc079ad8453a0160226e40b51
    Size: 3.52 MB
  4. python3.12-debug-3.12.1-4.el9_4.4.x86_64.rpm
    MD5: ada6163054356a308657ae5e68ea5a3b
    SHA-256: 101c38659847a632709a6830674688c9dfb5eb2f714503fc327f25d4bddbb4f5
    Size: 3.68 MB
  5. python3.12-devel-3.12.1-4.el9_4.4.i686.rpm
    MD5: a63231cc9f517d8e02dc9a05d7ba39d4
    SHA-256: 80fa9d353265b5e5ddfc51bb5925cd5eeae6d3d2a857ca4d5559dcb12b15d5f5
    Size: 325.82 kB
  6. python3.12-devel-3.12.1-4.el9_4.4.x86_64.rpm
    MD5: c153d50d2e7a3640719adc6e2f841b28
    SHA-256: 846d12d607ccc4d667128e474fe5334c7e402badfde9da62da9c965bd8dbf2db
    Size: 325.78 kB
  7. python3.12-idle-3.12.1-4.el9_4.4.i686.rpm
    MD5: 07e3358ecd3d3123f678abe31e9eec05
    SHA-256: 9dd22a6ca39a5e92751d65f326cb886db5a6fcd1ce4d09dce42bf2f7b2b59e00
    Size: 1.07 MB
  8. python3.12-idle-3.12.1-4.el9_4.4.x86_64.rpm
    MD5: e7bf47395c56b240e2f7762bcd88dafd
    SHA-256: 0f5b26a4a088d1067f0c72f1004dd4be846891dba4e121f5f50220928ea69f25
    Size: 1.07 MB
  9. python3.12-libs-3.12.1-4.el9_4.4.i686.rpm
    MD5: cc67bdf2f6818420e698117ebf397073
    SHA-256: c2024f122600a87da579b3be50727e690be2c8fbfdc6e1c3d88dcfae6d6cc908
    Size: 9.55 MB
  10. python3.12-libs-3.12.1-4.el9_4.4.x86_64.rpm
    MD5: 77070ac8ffbff1fbbf3d075657af9238
    SHA-256: 34a9f2551fbca4b841090c23b2ff943b6b02669411ba2f02dbf06e82995042aa
    Size: 9.47 MB
  11. python3.12-test-3.12.1-4.el9_4.4.i686.rpm
    MD5: 83a641dc34d05bd72c8d09059e6d075a
    SHA-256: de4a846d9105018cf14fcf9c193dc01a9d0c885107560fa5b2a1dbaf5d539198
    Size: 15.19 MB
  12. python3.12-test-3.12.1-4.el9_4.4.x86_64.rpm
    MD5: 642aee4c066455fcdc66d88314f22d29
    SHA-256: 980e1e8a75ebb5957076d39529a9b8e34fc2d54f81442c11f0cbf3fb890cdebb
    Size: 15.18 MB
  13. python3.12-tkinter-3.12.1-4.el9_4.4.i686.rpm
    MD5: f7a4dfdf50fb694777c1a8abd4738ad0
    SHA-256: 2fb0ee92641e60dd2e01546e5fe774c3ffa8187a858dbe8e956507bb8748d508
    Size: 419.08 kB
  14. python3.12-tkinter-3.12.1-4.el9_4.4.x86_64.rpm
    MD5: ff33ca768ffb7230cd1b04fe1479b34c
    SHA-256: 89cda9aca7b4380f1e441f2d18f607dd54ccec4454ccced15c68789ab3f1e208
    Size: 417.80 kB