RHSA-2017:0938: Moderate: python-defusedxml and python-pysaml2 security update
The defusedxml package contains several Python-only updates for security vulnerabilities in Python's XML libraries. Defusedxml functions and classes can be used instead of the originals to protect against entity-expansion and DTD-retrieval issues.PySAML2 is the python implementation of SAML Version 2, containing all the functionality for building a SAML2 service provider or an identity provider, to be used in a WSGI environment.Security Fix(es): An XML entity expansion vulnerability was found in python-pysaml2. A remote attacker could send a crafted request which would cause denial of service through resource exhaustion. (CVE-2016-10149)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2017:0938?
The severity of RHSA-2017:0938 is classified as moderate.
How do I fix RHSA-2017:0938?
To fix RHSA-2017:0938, update the python-defusedxml package to version 0.5.0-1.el7 or python-pysaml2 package to version 3.0.2-3.el7.
Which packages are affected by RHSA-2017:0938?
The affected packages in RHSA-2017:0938 are python-defusedxml and python-pysaml2.
What vulnerabilities does RHSA-2017:0938 address?
RHSA-2017:0938 addresses security vulnerabilities in Python's XML libraries related to entity-expansion and DTD-retrieval issues.
Is there a specific version required to remediate RHSA-2017:0938?
Yes, you need to upgrade to python-defusedxml 0.5.0-1.el7 or python-pysaml2 3.0.2-3.el7 to remediate RHSA-2017:0938.