UbuntuUpdates.org

Package "python3.8"

Name: python3.8

Description:

Interactive high-level object-oriented language (version 3.8)

Latest version: 3.8.10-0ubuntu1~20.04.10
Release: focal (20.04)
Level: security
Repository: main

Links


Download "python3.8"


Other versions of "python3.8" in Focal

Repository Area Version
base universe 3.8.2-1ubuntu1
base main 3.8.2-1ubuntu1
security universe 3.8.10-0ubuntu1~20.04.10
updates main 3.8.10-0ubuntu1~20.04.10
updates universe 3.8.10-0ubuntu1~20.04.10

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.8.10-0ubuntu1~20.04.5 2022-07-14 15:06:33 UTC

  python3.8 (3.8.10-0ubuntu1~20.04.5) focal-security; urgency=medium

  * SECURITY UPDATE: Injection Attack
    - debian/patches/CVE-2015-20107.patch: Make mailcap refuse to match unsafe
      filenames/types/param in Lib/mailcap.py, Lib/test/test_mailcap.py.
    - CVE-2015-20107

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 22 Jun 2022 17:18:18 -0300

Source diff to previous version
CVE-2015-20107 In Python (aka CPython) through 3.10.4, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This m

Version: 3.8.10-0ubuntu1~20.04.4 2022-03-28 11:06:23 UTC

  python3.8 (3.8.10-0ubuntu1~20.04.4) focal-security; urgency=medium

  * SECURITY UPDATE: Injection Attack
    - debian/patches/CVE-2022-0391.patch: sanitize urls in urllib.parse
      when it containing ASCII newline and tabs in
      Doc/library/urllib.parse.rst, Lib/test/test_urlparse.py,
      Lib/urllib/parse.py.
    - CVE-2022-0391
  * Skipping test_idle in riscv64 arch
    - debian/rules: adding test_idle to TEST_EXCLUDES in riscv64 arch due it
      hangs in build time.

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 15 Mar 2022 09:22:08 -0300

Source diff to previous version
CVE-2022-0391 A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into componen

Version: 3.8.10-0ubuntu1~20.04.2 2021-12-15 22:06:19 UTC

  python3.8 (3.8.10-0ubuntu1~20.04.2) focal-security; urgency=medium

  * SECURITY UPDATE: Denial of Service
     - debian/patches/CVE-2021-3737.patch: addresses the potential for the
       urllib http client to enter into an infinite loop and hang on a 100
       Continue response from a malicious server.
     - debian/patches/CVE-2021-3737_test-fix.patch: improves the regression
       test in Lib/test/test_httplib.py
     - CVE-2021-3737_test-fix.patch

 -- Ian Constantin <email address hidden> Fri, 26 Nov 2021 15:14:08 -0500

Source diff to previous version
CVE-2021-3737 client can enter an infinite loop on a 100 Continue response from the server

Version: 3.8.10-0ubuntu1~20.04.1 2021-10-04 15:06:25 UTC

  python3.8 (3.8.10-0ubuntu1~20.04.1) focal-security; urgency=medium

  [ Marc Deslauriers ]
  * SECURITY UPDATE: improper handling of octal strings in ipaddress
    - debian/patches/CVE-2021-29921.patch: no longer tolerate leading zeros
      in IPv4 addresses in Lib/ipaddress.py, Lib/test/test_ipaddress.py.
    - CVE-2021-29921

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 28 Sep 2021 13:10:42 -0300

Source diff to previous version
CVE-2021-29921 In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) all

Version: 3.8.10-0ubuntu1~20.04 2021-06-30 15:06:26 UTC

  python3.8 (3.8.10-0ubuntu1~20.04) focal-proposed; urgency=medium

  * SRU: LP: #1928057. Backport Python 3.8.10 to 20.04 LTS.
  * Python 3.8.10 release.
  * Refresh patches.
  * Call python with -S when checking the minimal set of modules.
  * Try to detect whether python3-venv is missing (Stefano Rivera).
    Addresses: #977887.
  * Build a python3.8-full package.

1928057 SRU: backport Python 3.8.10 to 20.04 LTS and 20.10



About   -   Send Feedback to @ubuntu_updates