Slackware: 2022-341-01: python3 Security Update
Summary
Here are the details from the Slackware 15.0 ChangeLog: patches/packages/python3-3.9.16-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: gh-98739: Updated bundled libexpat to 2.5.0 to fix CVE-2022-43680 (heap use-after-free). gh-98433: The IDNA codec decoder used on DNS hostnames by socket or asyncio related name resolution functions no longer involves a quadratic algorithm to fix CVE-2022-45061. This prevents a potential CPU denial of service if an out-of-spec excessive length hostname involving bidirectional characters were decoded. Some protocols such as urllib http 3xx redirects potentially allow for an attacker to supply such a name. gh-100001: python -m http.server no longer allows terminal control characters sent within a garbage request to be printed to the stderr server log. gh-87604: Avoid publishing list of active per-interpreter audit hooks via the gc module. gh-97514: On Linux the multiprocessing module returns to using file...
Where Find New Packages
Thanks to the friendly folks at the OSU Open Source Lab
(https://osuosl.org/) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for
additional mirror sites near you.
Updated package for Slackware 15.0:
Updated package for Slackware x86_64 15.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:
MD5 Signatures
Slackware 15.0 package:
35b47a72e146ac3e8b9f07f77623a22b python3-3.9.16-i586-1_slack15.0.txz
Slackware x86_64 15.0 package:
f476c223e996bc362fb9491776122306 python3-3.9.16-x86_64-1_slack15.0.txz
Slackware -current package:
5608f4d944d918fbac0da5e0d090c82c d/python3-3.9.16-i586-1.txz
Slackware x86_64 -current package:
bddb9d9fd13a6e39a3ce4fde267a9d6f d/python3-3.9.16-x86_64-1.txz
Installation Instructions
Installation instructions: Upgrade the package as root: # upgradepkg python3-3.9.16-i586-1_slack15.0.txz