-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.3154
             [SECURITY] [DLA 1889-1] python3.4 security update
                              19 August 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           python3.4
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
Impact/Access:     Access Confidential Data -- Remote/Unauthenticated
Resolution:        Patch/Upgrade
CVE Names:         CVE-2018-20852  

Reference:         ESB-2019.3079
                   ESB-2019.3061
                   ESB-2019.2955

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2019/08/msg00022.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : python3.4
Version        : 3.4.2-1+deb8u6
CVE ID         : CVE-2018-20852


A vulnerability has been discovered in Python, an interactive high-level 
object-oriented language, that is relevant for cookie handling.
By using a malicious server an attacker might steal cookies that are 
meant for other domains


For Debian 8 "Jessie", this problem has been fixed in version
3.4.2-1+deb8u6.

We recommend that you upgrade your python3.4 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

- -----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAl1YP5RfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy
MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7
WEeS8A//ZYeHW6D/GJaFnyRK2LlnPX+jhYpuY5/1J4VTGenq5yewYwTGtf2WA1td
um7Mo8ssLVshlRxeE6CoIJ32+ZSPQh4TFyL7KqIHNfwLgA83mkGKKDgtJjwvQ1rn
6VLdLEVuWpwmpgSsRm/bp5sv230Mf/edkFpl9NKxHb/pe5xxXimoEd7WjXvLOafE
AsbqLEngpHArAfpA3/CwhelGmg0QzUj1Sfy/DYwec2ZvPFrXfUByteAtwkf926eV
lGZh7lIC1b90udg2OUd0B8BGuqmqJUZy/cLfV8Z2TeW0o7hhJWYGd5Xwo7Z86ozm
0GpO9UEUnJDUd08k0kncgrKFw1KV46VYurunhoW6jFFvjSkvcRZUD+cKnCYrT8w3
CX1VM91k9pJqHKt5kKhhaZHl2FBWY/eLhgwaJWpDuAAz3W5J9LWcKJLDdExSkOZh
4EzqQnjzmd+KmTIhhI1IFNnn++gIYWqOWrhN9fScHZg75n0qPwLFJVP9GgALTtaO
WdKAwPCF9ezgAkn0lZtuPCgJxQFAA2vc204NflwK5RCEBD6EuIXjKxExMFm9b0Oa
kkvFiEDpaD7Oc116x0tLbndf3/4GtYLg2eRxhbJUSijU8IYzn+o5w+TI13/kUTHw
DvxlOIT2ah5DHh/FuvmQfNP59zCdtJ4UenXYv7AUpE3xMbsYHwI=
=Sape
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXVnb8maOgq3Tt24GAQg1IA//SOQAAqaQGAXlQH/W+uUGyI0pZikEnHAb
F2Q1iih/UEbL5gWvs/5Tq25Rk3h0vhmYAk8DWfcQE2O0CUNp3QavWBjQe+IcWa8h
11nAu9EXCPboVbZSM4kTBNl6SSrSBmbGB1xFbDXITpb0bs+0a3gYMttnh8o+Uqun
hvG8cYC8cPskOkCnrvPNceF6bpYDc7rYYXW3rsGruJC6hdseDbnEnmB3zCV1dNfd
BS4idVqjz3ylYdMXpGqZ5UxPfGBvd7Xyv2U8SIrMAP6P9eHrUVDTZ4UeJIiPjgwu
X+VMREc+A2IYSHmyec+xBi0hevt1n/mfftgI0E2/JtrtYxurrbmsaOMi3PhNQm3U
Y1qlV4Tzyoz+QZEaEIdMS/fiZXW0lXbXblw23qZ7J+9EWfvbYxAEnNAHTExnirAd
ZcH6iK4rEK9gev6oTfJph4/Bn2nuLO1XYkHeGy6l06x/S1afbPj0PqWk0lCOfD6K
9ez774U3v7VAztk32jQ3Br6vafERgmJIaLyp7FoOOU1wZ79cKJEM5Zu44kWvGOmJ
i/IDVnECPHTakVxgnWey92krB5zvXXK7nMUL0lYx2pVpPGxKe424XkJhEhZe17ck
03PkMVDMC72bnW2f18MNpZu1pyK83Z6vvOfwf7kTkCF4cmi+vUDexyOgLBVd3Q2x
sVyPn/lRfLw=
=B9HZ
-----END PGP SIGNATURE-----