RHSA-2022:7592: Moderate: python39:3.9 and python39-devel:3.9 security update
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.Security Fix(es): python: mailcap: findmatch() function does not sanitize the second argument (CVE-2015-20107) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/numpyto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python-cffito a version that resolves this vulnerability.Fixed in 1.14.3-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-chardetto a version that resolves this vulnerability.Fixed in 3.0.4-19.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-cryptographyto a version that resolves this vulnerability.Fixed in 3.3.1-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-idnato a version that resolves this vulnerability.Fixed in 2.10-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-lxmlto a version that resolves this vulnerability.Fixed in 4.6.5-1.module+el8.6.0+13933+9cf0c87c - Upgrade
Upgrade
redhat/python-plyto a version that resolves this vulnerability.Fixed in 3.11-10.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-psutilto a version that resolves this vulnerability.Fixed in 5.8.0-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-psycopg2to a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-pycparserto a version that resolves this vulnerability.Fixed in 2.20-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-pysocksto a version that resolves this vulnerability.Fixed in 1.7.1-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-requeststo a version that resolves this vulnerability.Fixed in 2.25.0-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-tomlto a version that resolves this vulnerability.Fixed in 0.10.1-5.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-urllib3to a version that resolves this vulnerability.Fixed in 1.25.10-4.module+el8.5.0+11712+ea2d2be1 - Upgrade
Upgrade
redhat/python-wheelto a version that resolves this vulnerability.Fixed in 0.35.1-4.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39to a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python3x-pipto a version that resolves this vulnerability.Fixed in 20.2.4-7.module+el8.6.0+13003+6bb2c488 - Upgrade
Upgrade
redhat/python3x-setuptoolsto a version that resolves this vulnerability.Fixed in 50.3.2-4.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python3x-sixto a version that resolves this vulnerability.Fixed in 1.15.0-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/scipyto a version that resolves this vulnerability.Fixed in 1.5.4-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/numpy-debugsourceto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python-cffi-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.3-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-cryptography-debugsourceto a version that resolves this vulnerability.Fixed in 3.3.1-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-lxml-debugsourceto a version that resolves this vulnerability.Fixed in 4.6.5-1.module+el8.6.0+13933+9cf0c87c - Upgrade
Upgrade
redhat/python-psutil-debugsourceto a version that resolves this vulnerability.Fixed in 5.8.0-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-psycopg2-debugsourceto a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-cffito a version that resolves this vulnerability.Fixed in 1.14.3-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-cffi-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.3-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-chardetto a version that resolves this vulnerability.Fixed in 3.0.4-19.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-cryptographyto a version that resolves this vulnerability.Fixed in 3.3.1-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-cryptography-debuginfoto a version that resolves this vulnerability.Fixed in 3.3.1-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-debuginfoto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-debugsourceto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-develto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-idleto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-idnato a version that resolves this vulnerability.Fixed in 2.10-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-libsto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-lxmlto a version that resolves this vulnerability.Fixed in 4.6.5-1.module+el8.6.0+13933+9cf0c87c - Upgrade
Upgrade
redhat/python39-lxml-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.5-1.module+el8.6.0+13933+9cf0c87c - Upgrade
Upgrade
redhat/python39-numpyto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39-numpy-debuginfoto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39-numpy-docto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39-numpy-f2pyto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39-pipto a version that resolves this vulnerability.Fixed in 20.2.4-7.module+el8.6.0+13003+6bb2c488 - Upgrade
Upgrade
redhat/python39-pip-wheelto a version that resolves this vulnerability.Fixed in 20.2.4-7.module+el8.6.0+13003+6bb2c488 - Upgrade
Upgrade
redhat/python39-plyto a version that resolves this vulnerability.Fixed in 3.11-10.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-psutilto a version that resolves this vulnerability.Fixed in 5.8.0-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-psutil-debuginfoto a version that resolves this vulnerability.Fixed in 5.8.0-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-psycopg2to a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-psycopg2-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-psycopg2-docto a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-psycopg2-teststo a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-pycparserto a version that resolves this vulnerability.Fixed in 2.20-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-pysocksto a version that resolves this vulnerability.Fixed in 1.7.1-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-pyyamlto a version that resolves this vulnerability.Fixed in 5.4.1-1.module+el8.5.0+10613+59a13ec4 - Upgrade
Upgrade
redhat/python39-pyyaml-debuginfoto a version that resolves this vulnerability.Fixed in 5.4.1-1.module+el8.5.0+10613+59a13ec4 - Upgrade
Upgrade
redhat/python39-requeststo a version that resolves this vulnerability.Fixed in 2.25.0-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-rpm-macrosto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-scipyto a version that resolves this vulnerability.Fixed in 1.5.4-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-scipy-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.4-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-setuptoolsto a version that resolves this vulnerability.Fixed in 50.3.2-4.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39-setuptools-wheelto a version that resolves this vulnerability.Fixed in 50.3.2-4.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39-sixto a version that resolves this vulnerability.Fixed in 1.15.0-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-testto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-tkinterto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-tomlto a version that resolves this vulnerability.Fixed in 0.10.1-5.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-urllib3to a version that resolves this vulnerability.Fixed in 1.25.10-4.module+el8.5.0+11712+ea2d2be1 - Upgrade
Upgrade
redhat/python39-wheelto a version that resolves this vulnerability.Fixed in 0.35.1-4.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/python39-wheel-wheelto a version that resolves this vulnerability.Fixed in 0.35.1-4.module+el8.5.0+12204+54860423 - Upgrade
Upgrade
redhat/scipy-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.4-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/numpy-debugsourceto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423.aa - Upgrade
Upgrade
redhat/python-cffi-debugsourceto a version that resolves this vulnerability.Fixed in 1.14.3-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python-cryptography-debugsourceto a version that resolves this vulnerability.Fixed in 3.3.1-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python-lxml-debugsourceto a version that resolves this vulnerability.Fixed in 4.6.5-1.module+el8.6.0+13933+9cf0c87c.aa - Upgrade
Upgrade
redhat/python-psutil-debugsourceto a version that resolves this vulnerability.Fixed in 5.8.0-4.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python-psycopg2-debugsourceto a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39to a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-cffito a version that resolves this vulnerability.Fixed in 1.14.3-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-cffi-debuginfoto a version that resolves this vulnerability.Fixed in 1.14.3-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-cryptographyto a version that resolves this vulnerability.Fixed in 3.3.1-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-cryptography-debuginfoto a version that resolves this vulnerability.Fixed in 3.3.1-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-debuginfoto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-debugsourceto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-develto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-idleto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-libsto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-lxmlto a version that resolves this vulnerability.Fixed in 4.6.5-1.module+el8.6.0+13933+9cf0c87c.aa - Upgrade
Upgrade
redhat/python39-lxml-debuginfoto a version that resolves this vulnerability.Fixed in 4.6.5-1.module+el8.6.0+13933+9cf0c87c.aa - Upgrade
Upgrade
redhat/python39-numpyto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423.aa - Upgrade
Upgrade
redhat/python39-numpy-debuginfoto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423.aa - Upgrade
Upgrade
redhat/python39-numpy-f2pyto a version that resolves this vulnerability.Fixed in 1.19.4-3.module+el8.5.0+12204+54860423.aa - Upgrade
Upgrade
redhat/python39-psutilto a version that resolves this vulnerability.Fixed in 5.8.0-4.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-psutil-debuginfoto a version that resolves this vulnerability.Fixed in 5.8.0-4.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-psycopg2to a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-psycopg2-debuginfoto a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-psycopg2-docto a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-psycopg2-teststo a version that resolves this vulnerability.Fixed in 2.8.6-2.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-pyyamlto a version that resolves this vulnerability.Fixed in 5.4.1-1.module+el8.5.0+10613+59a13ec4.aa - Upgrade
Upgrade
redhat/python39-pyyaml-debuginfoto a version that resolves this vulnerability.Fixed in 5.4.1-1.module+el8.5.0+10613+59a13ec4.aa - Upgrade
Upgrade
redhat/python39-scipyto a version that resolves this vulnerability.Fixed in 1.5.4-3.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-scipy-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.4-3.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/python39-testto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-tkinterto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/scipy-debugsourceto a version that resolves this vulnerability.Fixed in 1.5.4-3.module+el8.4.0+9822+20bf1249.aa - Upgrade
Upgrade
redhat/pybind11to a version that resolves this vulnerability.Fixed in 2.7.1-1.module+el8.6.0+12838+640e6226 - Upgrade
Upgrade
redhat/pytestto a version that resolves this vulnerability.Fixed in 6.0.2-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-attrsto a version that resolves this vulnerability.Fixed in 20.3.0-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-iniconfigto a version that resolves this vulnerability.Fixed in 1.1.1-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-more-itertoolsto a version that resolves this vulnerability.Fixed in 8.5.0-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-packagingto a version that resolves this vulnerability.Fixed in 20.4-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-pluggyto a version that resolves this vulnerability.Fixed in 0.13.1-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-pyto a version that resolves this vulnerability.Fixed in 1.10.0-1.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python-wcwidthto a version that resolves this vulnerability.Fixed in 0.2.5-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python3x-pyparsingto a version that resolves this vulnerability.Fixed in 2.4.7-5.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-attrsto a version that resolves this vulnerability.Fixed in 20.3.0-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-debugto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257 - Upgrade
Upgrade
redhat/python39-iniconfigto a version that resolves this vulnerability.Fixed in 1.1.1-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-more-itertoolsto a version that resolves this vulnerability.Fixed in 8.5.0-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-packagingto a version that resolves this vulnerability.Fixed in 20.4-4.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-pluggyto a version that resolves this vulnerability.Fixed in 0.13.1-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-pyto a version that resolves this vulnerability.Fixed in 1.10.0-1.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-pybind11to a version that resolves this vulnerability.Fixed in 2.7.1-1.module+el8.6.0+12838+640e6226 - Upgrade
Upgrade
redhat/python39-pybind11-develto a version that resolves this vulnerability.Fixed in 2.7.1-1.module+el8.6.0+12838+640e6226 - Upgrade
Upgrade
redhat/python39-pyparsingto a version that resolves this vulnerability.Fixed in 2.4.7-5.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-pytestto a version that resolves this vulnerability.Fixed in 6.0.2-2.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-wcwidthto a version that resolves this vulnerability.Fixed in 0.2.5-3.module+el8.4.0+9822+20bf1249 - Upgrade
Upgrade
redhat/python39-debugto a version that resolves this vulnerability.Fixed in 3.9.13-1.module+el8.7.0+15656+ffd4a257.aa - Upgrade
Upgrade
redhat/python39-pybind11to a version that resolves this vulnerability.Fixed in 2.7.1-1.module+el8.6.0+12838+640e6226.aa - Upgrade
Upgrade
redhat/python39-pybind11-develto a version that resolves this vulnerability.Fixed in 2.7.1-1.module+el8.6.0+12838+640e6226.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:7592?
The vulnerability RHSA-2022:7592 is classified with moderate severity.
How do I fix RHSA-2022:7592?
To fix RHSA-2022:7592, update to the recommended version of the affected packages listed in the advisory.
What packages are affected by RHSA-2022:7592?
RHSA-2022:7592 affects various Python-related packages including numpy, python-cffi, python-cryptography, and python-lxml.
Is there a workaround for RHSA-2022:7592?
There are no official workarounds for RHSA-2022:7592; upgrading is the recommended action.
When was the advisory for RHSA-2022:7592 released?
The advisory for RHSA-2022:7592 was released on December 21, 2022.