Red Hat Security Advisory: python38:3.8 and python38-devel:3.8 security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2007-4559 — python: tarfile module directory traversal CVE-2023-32681 — python-requests: Unintended leak of Proxy-Authorization header
🎯 Affected products200
- Red Hat CodeReady Linux Builder (v. 8)
- Red Hat Enterprise Linux AppStream (v. 8)
- Cython-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- PyYAML-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- babel-0:2.7.0-11.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- mod_wsgi-0:4.6.8-5.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- numpy-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- pytest-0:4.6.6-3.module+el8.9.0+19592+4b459c9b.src (python38-devel:3.8) as a component of Red Hat CodeReady Linux Builder (v. 8)
- python-PyMySQL-0:0.10.1-1.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- python-asn1crypto-0:1.2.0-3.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- python-atomicwrites-0:1.3.0-8.module+el8.9.0+19592+4b459c9b.src (python38-devel:3.8) as a component of Red Hat CodeReady Linux Builder (v. 8)
- python-attrs-0:19.3.0-3.module+el8.9.0+19592+4b459c9b.src (python38-devel:3.8) as a component of Red Hat CodeReady Linux Builder (v. 8)
- python-cffi-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- python-chardet-0:3.0.4-19.module+el8.9.0+19592+4b459c9b.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Do not extract archives from untrusted sources with the Python tarfile module. Users of the module should add sanity checks when calling the tarfile.extract or tarfile.extractall functions. Workaround: For users who are not able to update Requests immediately, there is one potential workaround. You may disable redirects by setting allow_redirects to False on all calls through Requests top-level APIs. Note that if you are currently relying on redirect behaviors, you will need to capture the 3xx response codes and ensure a new request is made to the redirect destination. import requests r = requests.get('http://github.com/', allow_redirects=False)
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2023:7050
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.9_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=263261
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2209469
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213594
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2213847
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2217853
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2217862
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2218267
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2222717
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_7050.json