ELSA-2023-3550

ELSA-2023-3550 - python security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2023-06-26

Description


[2.6.6-68.0.3]
- ASCII newline and tab characters are stripped from the URL [CVE-2022-0391][Orabug: 35479836]
- Start stripping C0 control and space chars in urlsplit [CVE-2023-24329][Orabug: 35479836]


Related CVEs


CVE-2022-0391
CVE-2023-24329

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) python-2.6.6-68.0.3.el6_10.src.rpmddeb584e04f7741af5fde6ef6199f46b-
python-2.6.6-68.0.3.el6_10.i686.rpm28cbb6c7f2f446fa2f07032f8242e949-
python-devel-2.6.6-68.0.3.el6_10.i686.rpmc22f6145ecb3b78c79763dfced7a3fd6-
python-libs-2.6.6-68.0.3.el6_10.i686.rpmed2ed262de7fc18a6d1a0d2b7b07c44f-
python-test-2.6.6-68.0.3.el6_10.i686.rpm754f6c5528c047237006117e14abb3af-
python-tools-2.6.6-68.0.3.el6_10.i686.rpmfe5694ff8b03cd9f3f8a3b978e6c3f44-
tkinter-2.6.6-68.0.3.el6_10.i686.rpmd31fc10618727929998c6bc9c12a7eca-
Oracle Linux 6 (x86_64) python-2.6.6-68.0.3.el6_10.src.rpmddeb584e04f7741af5fde6ef6199f46b-
python-2.6.6-68.0.3.el6_10.i686.rpm28cbb6c7f2f446fa2f07032f8242e949-
python-2.6.6-68.0.3.el6_10.x86_64.rpm53213abb4a72c11da822676763dd900f-
python-devel-2.6.6-68.0.3.el6_10.i686.rpmc22f6145ecb3b78c79763dfced7a3fd6-
python-devel-2.6.6-68.0.3.el6_10.x86_64.rpmd0371a2a54f041ee06f991b9a3f663bb-
python-libs-2.6.6-68.0.3.el6_10.i686.rpmed2ed262de7fc18a6d1a0d2b7b07c44f-
python-libs-2.6.6-68.0.3.el6_10.x86_64.rpm8fe362ab4f697b9f866c8ca5609061c6-
python-test-2.6.6-68.0.3.el6_10.x86_64.rpm5bb27301198c8ddeac5c822dbdff584c-
python-tools-2.6.6-68.0.3.el6_10.x86_64.rpm40512c3cc70e6f424bd6d55112f67f11-
tkinter-2.6.6-68.0.3.el6_10.x86_64.rpm3bafa709d3299ec1a9306214b9e4eefc-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete