RHSA-2023:7050MediumCVSS 6.1

Red Hat Security Advisory: python38:3.8 and python38-devel:3.8 security update

Published
November 14, 2023
Last Modified
August 19, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2007-4559 — python: tarfile module directory traversal CVE-2023-32681 — python-requests: Unintended leak of Proxy-Authorization header

🎯 Affected products200

  • Red Hat CodeReady Linux Builder (v. 8)
  • Red Hat Enterprise Linux AppStream (v. 8)
  • Cython-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • Cython-debugsource-0:0.29.14-4.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • PyYAML-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • PyYAML-debugsource-0:5.4.1-1.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • babel-0:2.7.0-11.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • mod_wsgi-0:4.6.8-5.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • numpy-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • numpy-debugsource-0:1.17.3-7.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • pytest-0:4.6.6-3.module+el8.9.0+19592+4b459c9b.src (python38-devel:3.8) as a component of Red Hat CodeReady Linux Builder (v. 8)
  • python-PyMySQL-0:0.10.1-1.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • python-asn1crypto-0:1.2.0-3.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • python-atomicwrites-0:1.3.0-8.module+el8.9.0+19592+4b459c9b.src (python38-devel:3.8) as a component of Red Hat CodeReady Linux Builder (v. 8)
  • python-attrs-0:19.3.0-3.module+el8.9.0+19592+4b459c9b.src (python38-devel:3.8) as a component of Red Hat CodeReady Linux Builder (v. 8)
  • python-cffi-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.aarch64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.ppc64le (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.s390x (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • python-cffi-debugsource-0:1.13.2-3.module+el8.9.0+19598+4a60c7b7.x86_64 (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • python-chardet-0:3.0.4-19.module+el8.9.0+19592+4b459c9b.src (python38:3.8) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Do not extract archives from untrusted sources with the Python tarfile module. Users of the module should add sanity checks when calling the tarfile.extract or tarfile.extractall functions. Workaround: For users who are not able to update Requests immediately, there is one potential workaround. You may disable redirects by setting allow_redirects to False on all calls through Requests top-level APIs. Note that if you are currently relying on redirect behaviors, you will need to capture the 3xx response codes and ensure a new request is made to the redirect destination. import requests r = requests.get('http://github.com/', allow_redirects=False)

🔗 References (13)