python-gevent-1.2.2-5.el8_10

エラータID: AXSA:2024-8990:01

Release date: 
Wednesday, November 13, 2024 - 21:42
Subject: 
python-gevent-1.2.2-5.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

gevent is a coroutine-based Python networking library that uses greenlet to provide a high-level synchronous API on top of libevent event loop. Features include: * convenient API around greenlets * familiar synchronization primitives (gevent.event, gevent.queue) * socket module that cooperates * WSGI server on top of libevent-http * DNS requests done through libevent-dns * monkey patching utility to get pure Python modules to cooperate

Security Fix(es):

* python-gevent: privilege escalation via a crafted script to the WSGIServer component (CVE-2023-41419)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-41419
An issue in Gevent before version 23.9.0 allows a remote attacker to escalate privileges via a crafted script to the WSGIServer component.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python-gevent-1.2.2-5.el8_10.src.rpm
    MD5: 1069d90d3f721418191a84ae969ff988
    SHA-256: 73646f0ce815447454a536de04851dc5c0ea9ab8bdd7b8490bcafa2ea809b42a
    Size: 3.03 MB

Asianux Server 8 for x86_64
  1. python3-gevent-1.2.2-5.el8_10.x86_64.rpm
    MD5: 10112238d8e137518b0405fba5e6359e
    SHA-256: 1e5630d769b8acb089cfe2f5e12b4022f460a302e5b1676f56b7d38ebbd039f9
    Size: 500.21 kB