RHSA-2020:4273MediumCVSS 8.0
Red Hat Security Advisory: python27 security, bug fix, and enhancement update
🔗 CVE IDs covered (4)
📋 Description
CVE-2019-18348 — python: CRLF injection via the host part of the url passed to urlopen() CVE-2019-20907 — python: infinite loop in the tarfile module via crafted TAR archive CVE-2019-20916 — python-pip: directory traversal in _download_http_url() function in src/pip/_internal/download.py CVE-2020-26116 — python: CRLF injection via HTTP request method in httplib/http.client
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2020:4273
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1727276
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1856481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1868135
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1882656
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1883014
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_4273.json