RHSA-2019:3335: Moderate: python27:2.7 security and bug fix update
Python is an interpreted, interactive, object-oriented programming language that supports modules, classes, exceptions, high-level dynamic data types, and dynamic typing.Security Fix(es): numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution (CVE-2019-6446) python: CRLF injection via the query part of the url passed to urlopen() (CVE-2019-9740) python: CRLF injection via the path part of the url passed to urlopen() (CVE-2019-9947) python: Undocumented localfile protocol allows remote attackers to bypass protection mechanisms (CVE-2019-9948) python-urllib3: CRLF injection due to not encoding the '\r\n' sequence leading to possible attack on internal service (CVE-2019-11236) python-urllib3: Certification mishandle when error should be thrown (CVE-2019-11324) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/babelto a version that resolves this vulnerability.Fixed in 2.5.1-9.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/numpyto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/pytestto a version that resolves this vulnerability.Fixed in 3.4.2-13.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-attrsto a version that resolves this vulnerability.Fixed in 17.4.0-10.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-backportsto a version that resolves this vulnerability.Fixed in 1.0-15.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-chardetto a version that resolves this vulnerability.Fixed in 3.0.4-10.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-coverageto a version that resolves this vulnerability.Fixed in 4.5.1-4.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-dnsto a version that resolves this vulnerability.Fixed in 1.15.0-10.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-docsto a version that resolves this vulnerability.Fixed in 2.7.16-2.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-docutilsto a version that resolves this vulnerability.Fixed in 0.14-12.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-funcsigsto a version that resolves this vulnerability.Fixed in 1.0.2-13.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-idnato a version that resolves this vulnerability.Fixed in 2.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-ipaddressto a version that resolves this vulnerability.Fixed in 1.0.18-6.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-jinja2to a version that resolves this vulnerability.Fixed in 2.10-8.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-lxmlto a version that resolves this vulnerability.Fixed in 4.2.3-3.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-markupsafeto a version that resolves this vulnerability.Fixed in 0.23-19.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-mockto a version that resolves this vulnerability.Fixed in 2.0.0-13.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-noseto a version that resolves this vulnerability.Fixed in 1.3.7-30.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-pluggyto a version that resolves this vulnerability.Fixed in 0.6.0-8.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-psycopg2to a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-pyto a version that resolves this vulnerability.Fixed in 1.5.3-6.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-pygmentsto a version that resolves this vulnerability.Fixed in 2.2.0-20.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-pymongoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python-pysocksto a version that resolves this vulnerability.Fixed in 1.6.8-6.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-pytest-mockto a version that resolves this vulnerability.Fixed in 1.9.0-4.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-requeststo a version that resolves this vulnerability.Fixed in 2.20.0-2.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-sixto a version that resolves this vulnerability.Fixed in 1.11.0-5.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-sqlalchemyto a version that resolves this vulnerability.Fixed in 1.3.2-1.module+el8.1.0+2994+98e054d6 - Upgrade
Upgrade
redhat/python-urllib3to a version that resolves this vulnerability.Fixed in 1.24.2-1.module+el8.1.0+3280+19512f10 - Upgrade
Upgrade
redhat/python-virtualenvto a version that resolves this vulnerability.Fixed in 15.1.0-19.module+el8.1.0+3507+d69c168d - Upgrade
Upgrade
redhat/python-wheelto a version that resolves this vulnerability.Fixed in 0.31.1-2.module+el8.1.0+3725+aac5cd17 - Upgrade
Upgrade
redhat/python2to a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-pipto a version that resolves this vulnerability.Fixed in 9.0.3-14.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-rpm-macrosto a version that resolves this vulnerability.Fixed in 3-38.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-setuptoolsto a version that resolves this vulnerability.Fixed in 39.0.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/pytzto a version that resolves this vulnerability.Fixed in 2017.2-12.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/scipyto a version that resolves this vulnerability.Fixed in 1.0.0-20.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/numpy-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/python-coverage-debugsourceto a version that resolves this vulnerability.Fixed in 4.5.1-4.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-lxml-debugsourceto a version that resolves this vulnerability.Fixed in 4.2.3-3.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-nose-docsto a version that resolves this vulnerability.Fixed in 1.3.7-30.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-psycopg2-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-psycopg2-debugsourceto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-psycopg2-docto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python-pymongo-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python-pymongo-debugsourceto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python-sqlalchemy-docto a version that resolves this vulnerability.Fixed in 1.3.2-1.module+el8.1.0+2994+98e054d6 - Upgrade
Upgrade
redhat/python2-attrsto a version that resolves this vulnerability.Fixed in 17.4.0-10.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-babelto a version that resolves this vulnerability.Fixed in 2.5.1-9.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-backportsto a version that resolves this vulnerability.Fixed in 1.0-15.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-bsonto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-bson-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-chardetto a version that resolves this vulnerability.Fixed in 3.0.4-10.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-coverageto a version that resolves this vulnerability.Fixed in 4.5.1-4.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-coverage-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.1-4.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-debugto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-debugsourceto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-develto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-dnsto a version that resolves this vulnerability.Fixed in 1.15.0-10.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-docsto a version that resolves this vulnerability.Fixed in 2.7.16-2.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-docs-infoto a version that resolves this vulnerability.Fixed in 2.7.16-2.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-docutilsto a version that resolves this vulnerability.Fixed in 0.14-12.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-funcsigsto a version that resolves this vulnerability.Fixed in 1.0.2-13.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-idnato a version that resolves this vulnerability.Fixed in 2.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-ipaddressto a version that resolves this vulnerability.Fixed in 1.0.18-6.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-jinja2to a version that resolves this vulnerability.Fixed in 2.10-8.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-libsto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-lxmlto a version that resolves this vulnerability.Fixed in 4.2.3-3.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-lxml-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.3-3.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-markupsafeto a version that resolves this vulnerability.Fixed in 0.23-19.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-mockto a version that resolves this vulnerability.Fixed in 2.0.0-13.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-noseto a version that resolves this vulnerability.Fixed in 1.3.7-30.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-numpyto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/python2-numpy-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/python2-numpy-docto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/python2-numpy-f2pyto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/python2-pip-wheelto a version that resolves this vulnerability.Fixed in 9.0.3-14.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-pluggyto a version that resolves this vulnerability.Fixed in 0.6.0-8.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-psycopg2to a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-psycopg2-debugto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-psycopg2-debug-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-psycopg2-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-psycopg2-teststo a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pyto a version that resolves this vulnerability.Fixed in 1.5.3-6.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pygmentsto a version that resolves this vulnerability.Fixed in 2.2.0-20.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pymongoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-pymongo-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-pymongo-gridfsto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-pysocksto a version that resolves this vulnerability.Fixed in 1.6.8-6.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pytestto a version that resolves this vulnerability.Fixed in 3.4.2-13.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pytest-mockto a version that resolves this vulnerability.Fixed in 1.9.0-4.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pytzto a version that resolves this vulnerability.Fixed in 2017.2-12.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pyyamlto a version that resolves this vulnerability.Fixed in 3.12-16.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-pyyaml-debuginfoto a version that resolves this vulnerability.Fixed in 3.12-16.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-requeststo a version that resolves this vulnerability.Fixed in 2.20.0-2.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-scipyto a version that resolves this vulnerability.Fixed in 1.0.0-20.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/python2-scipy-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-20.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/python2-setuptools-wheelto a version that resolves this vulnerability.Fixed in 39.0.1-11.module+el8.1.0+3446+c3d52da3 - Upgrade
Upgrade
redhat/python2-sixto a version that resolves this vulnerability.Fixed in 1.11.0-5.module+el8.1.0+3111+de3f2d8e - Upgrade
Upgrade
redhat/python2-sqlalchemyto a version that resolves this vulnerability.Fixed in 1.3.2-1.module+el8.1.0+2994+98e054d6 - Upgrade
Upgrade
redhat/python2-testto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-tkinterto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-toolsto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073 - Upgrade
Upgrade
redhat/python2-urllib3to a version that resolves this vulnerability.Fixed in 1.24.2-1.module+el8.1.0+3280+19512f10 - Upgrade
Upgrade
redhat/python2-virtualenvto a version that resolves this vulnerability.Fixed in 15.1.0-19.module+el8.1.0+3507+d69c168d - Upgrade
Upgrade
redhat/python2-wheelto a version that resolves this vulnerability.Fixed in 0.31.1-2.module+el8.1.0+3725+aac5cd17 - Upgrade
Upgrade
redhat/python2-wheel-wheelto a version that resolves this vulnerability.Fixed in 0.31.1-2.module+el8.1.0+3725+aac5cd17 - Upgrade
Upgrade
redhat/scipy-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-20.module+el8.1.0+3323+7ac3e00f - Upgrade
Upgrade
redhat/numpy-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f.aa - Upgrade
Upgrade
redhat/python-coverage-debugsourceto a version that resolves this vulnerability.Fixed in 4.5.1-4.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python-lxml-debugsourceto a version that resolves this vulnerability.Fixed in 4.2.3-3.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python-psycopg2-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python-psycopg2-debugsourceto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python-psycopg2-docto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python-pymongo-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3.aa - Upgrade
Upgrade
redhat/python-pymongo-debugsourceto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3.aa - Upgrade
Upgrade
redhat/python2to a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-backportsto a version that resolves this vulnerability.Fixed in 1.0-15.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-bsonto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3.aa - Upgrade
Upgrade
redhat/python2-bson-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3.aa - Upgrade
Upgrade
redhat/python2-coverageto a version that resolves this vulnerability.Fixed in 4.5.1-4.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-coverage-debuginfoto a version that resolves this vulnerability.Fixed in 4.5.1-4.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-debugto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-debugsourceto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-develto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-libsto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-lxmlto a version that resolves this vulnerability.Fixed in 4.2.3-3.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-lxml-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.3-3.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-markupsafeto a version that resolves this vulnerability.Fixed in 0.23-19.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-numpyto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f.aa - Upgrade
Upgrade
redhat/python2-numpy-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f.aa - Upgrade
Upgrade
redhat/python2-numpy-f2pyto a version that resolves this vulnerability.Fixed in 1.14.2-13.module+el8.1.0+3323+7ac3e00f.aa - Upgrade
Upgrade
redhat/python2-psycopg2to a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-psycopg2-debugto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-psycopg2-debug-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-psycopg2-debuginfoto a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-psycopg2-teststo a version that resolves this vulnerability.Fixed in 2.7.5-7.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-pymongoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3.aa - Upgrade
Upgrade
redhat/python2-pymongo-debuginfoto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3.aa - Upgrade
Upgrade
redhat/python2-pymongo-gridfsto a version that resolves this vulnerability.Fixed in 3.6.1-11.module+el8.1.0+3446+c3d52da3.aa - Upgrade
Upgrade
redhat/python2-pyyamlto a version that resolves this vulnerability.Fixed in 3.12-16.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-pyyaml-debuginfoto a version that resolves this vulnerability.Fixed in 3.12-16.module+el8.1.0+3111+de3f2d8e.aa - Upgrade
Upgrade
redhat/python2-scipyto a version that resolves this vulnerability.Fixed in 1.0.0-20.module+el8.1.0+3323+7ac3e00f.aa - Upgrade
Upgrade
redhat/python2-scipy-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.0-20.module+el8.1.0+3323+7ac3e00f.aa - Upgrade
Upgrade
redhat/python2-sqlalchemyto a version that resolves this vulnerability.Fixed in 1.3.2-1.module+el8.1.0+2994+98e054d6.aa - Upgrade
Upgrade
redhat/python2-testto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-tkinterto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/python2-toolsto a version that resolves this vulnerability.Fixed in 2.7.16-12.module+el8.1.0+4148+33a50073.aa - Upgrade
Upgrade
redhat/scipy-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.0-20.module+el8.1.0+3323+7ac3e00f.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3335?
The severity of RHSA-2019:3335 is classified as important.
How do I fix RHSA-2019:3335?
To fix RHSA-2019:3335, you need to update the affected packages to the versions specified in the advisory.
Which packages are affected by RHSA-2019:3335?
Affected packages include babel, numpy, pytest, python-attrs, and several other Python-related packages as noted in the advisory.
What vulnerabilities are addressed in RHSA-2019:3335?
This advisory addresses vulnerabilities related to crafted serialized objects passed in numpy.load() which could potentially lead to remote code execution.
Are there any alternative mitigations for RHSA-2019:3335?
While the recommended approach is to apply updates, alternative mitigations may include restricting access to affected functions and careful input validation.