Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.3154 [SECURITY] [DLA 1889-1] python3.4 security update 19 August 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: python3.4 Publisher: Debian Operating System: Debian GNU/Linux 8 Impact/Access: Access Confidential Data -- Remote/Unauthenticated Resolution: Patch/Upgrade CVE Names: CVE-2018-20852 Reference: ESB-2019.3079 ESB-2019.3061 ESB-2019.2955 Original Bulletin: https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Package : python3.4 Version : 3.4.2-1+deb8u6 CVE ID : CVE-2018-20852 A vulnerability has been discovered in Python, an interactive high-level object-oriented language, that is relevant for cookie handling. By using a malicious server an attacker might steal cookies that are meant for other domains For Debian 8 "Jessie", this problem has been fixed in version 3.4.2-1+deb8u6. We recommend that you upgrade your python3.4 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl1YP5RfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7 WEeS8A//ZYeHW6D/GJaFnyRK2LlnPX+jhYpuY5/1J4VTGenq5yewYwTGtf2WA1td um7Mo8ssLVshlRxeE6CoIJ32+ZSPQh4TFyL7KqIHNfwLgA83mkGKKDgtJjwvQ1rn 6VLdLEVuWpwmpgSsRm/bp5sv230Mf/edkFpl9NKxHb/pe5xxXimoEd7WjXvLOafE AsbqLEngpHArAfpA3/CwhelGmg0QzUj1Sfy/DYwec2ZvPFrXfUByteAtwkf926eV lGZh7lIC1b90udg2OUd0B8BGuqmqJUZy/cLfV8Z2TeW0o7hhJWYGd5Xwo7Z86ozm 0GpO9UEUnJDUd08k0kncgrKFw1KV46VYurunhoW6jFFvjSkvcRZUD+cKnCYrT8w3 CX1VM91k9pJqHKt5kKhhaZHl2FBWY/eLhgwaJWpDuAAz3W5J9LWcKJLDdExSkOZh 4EzqQnjzmd+KmTIhhI1IFNnn++gIYWqOWrhN9fScHZg75n0qPwLFJVP9GgALTtaO WdKAwPCF9ezgAkn0lZtuPCgJxQFAA2vc204NflwK5RCEBD6EuIXjKxExMFm9b0Oa kkvFiEDpaD7Oc116x0tLbndf3/4GtYLg2eRxhbJUSijU8IYzn+o5w+TI13/kUTHw DvxlOIT2ah5DHh/FuvmQfNP59zCdtJ4UenXYv7AUpE3xMbsYHwI= =Sape - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXVnb8maOgq3Tt24GAQg1IA//SOQAAqaQGAXlQH/W+uUGyI0pZikEnHAb F2Q1iih/UEbL5gWvs/5Tq25Rk3h0vhmYAk8DWfcQE2O0CUNp3QavWBjQe+IcWa8h 11nAu9EXCPboVbZSM4kTBNl6SSrSBmbGB1xFbDXITpb0bs+0a3gYMttnh8o+Uqun hvG8cYC8cPskOkCnrvPNceF6bpYDc7rYYXW3rsGruJC6hdseDbnEnmB3zCV1dNfd BS4idVqjz3ylYdMXpGqZ5UxPfGBvd7Xyv2U8SIrMAP6P9eHrUVDTZ4UeJIiPjgwu X+VMREc+A2IYSHmyec+xBi0hevt1n/mfftgI0E2/JtrtYxurrbmsaOMi3PhNQm3U Y1qlV4Tzyoz+QZEaEIdMS/fiZXW0lXbXblw23qZ7J+9EWfvbYxAEnNAHTExnirAd ZcH6iK4rEK9gev6oTfJph4/Bn2nuLO1XYkHeGy6l06x/S1afbPj0PqWk0lCOfD6K 9ez774U3v7VAztk32jQ3Br6vafERgmJIaLyp7FoOOU1wZ79cKJEM5Zu44kWvGOmJ i/IDVnECPHTakVxgnWey92krB5zvXXK7nMUL0lYx2pVpPGxKe424XkJhEhZe17ck 03PkMVDMC72bnW2f18MNpZu1pyK83Z6vvOfwf7kTkCF4cmi+vUDexyOgLBVd3Q2x sVyPn/lRfLw= =B9HZ -----END PGP SIGNATURE-----