UbuntuUpdates.org

Package "python3.10"

Name: python3.10

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • IDE for Python (v3.10) using Tkinter
  • Testsuite for the Python standard library (v3.10)
  • Python Interpreter with complete class library (version 3.10)
  • Python interpreter linked without PIE (version 3.10)

Latest version: 3.10.7-1ubuntu0.2
Release: kinetic (22.10)
Level: updates
Repository: universe

Links



Other versions of "python3.10" in Kinetic

Repository Area Version
base main 3.10.7-1
base universe 3.10.7-1
security main 3.10.7-1ubuntu0.2
security universe 3.10.7-1ubuntu0.2
updates main 3.10.7-1ubuntu0.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.10.7-1ubuntu0.2 2022-12-08 17:06:47 UTC

  python3.10 (3.10.7-1ubuntu0.2) kinetic-security; urgency=medium

  * SECURITY UPDATE: Buffer overflow
    - debian/patches/CVE-2022-37454.patch: fixes buffer overflow in
      Modules/_sha3/kcp/KeccakSponge.inc (LP: #1995197).
    - CVE-2022-37454
  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2022-45061.patch: fix quadratic time idna decoding
      in Lib/encodings/idna.py, Lib/test/test_codecs.py.
    - CVE-2022-45061

 -- Leonidas Da Silva Barbosa <email address hidden> Thu, 24 Nov 2022 16:45:47 -0300

Source diff to previous version
CVE-2022-37454 The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute
CVE-2022-45061 An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3

Version: 3.10.7-1ubuntu0.1 2022-11-03 14:07:22 UTC

  python3.10 (3.10.7-1ubuntu0.1) kinetic-security; urgency=medium

  * SECURITY UPDATE: privilege escalation via multiprocessing forkserver
    start method
    - debian/patches/CVE-2022-42919.patch: don't use Linux abstract sockets
      in Lib/multiprocessing/connection.py.
    - CVE-2022-42919

 -- Marc Deslauriers <email address hidden> Wed, 02 Nov 2022 14:49:29 -0400

CVE-2022-42919 Linux specific local privilege escalation via the multiprocessing forkserver start method



About   -   Send Feedback to @ubuntu_updates