RHEL 7 : python (RHSA-2020:1268)

Medium Nessus Plugin ID 135089

Synopsis

The remote Red Hat host is missing one or more security updates.

Description

The remote Redhat Enterprise Linux 7 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2020:1268 advisory.

- python: DOS via regular expression catastrophic backtracking in apop() method in pop3lib (CVE-2018-1060)

- python: DOS via regular expression backtracking in difflib.IS_LINE_JUNK method in difflib (CVE-2018-1061)

- python: Missing salt initialization in _elementtree.c module (CVE-2018-14647)

- python: CRLF injection via the query part of the url passed to urlopen() (CVE-2019-9740)

- python: CRLF injection via the path part of the url passed to urlopen() (CVE-2019-9947)

- python: Undocumented local_file protocol allows remote attackers to bypass protection mechanisms (CVE-2019-9948)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://cwe.mitre.org/data/definitions/20.html

https://cwe.mitre.org/data/definitions/20.html

https://cwe.mitre.org/data/definitions/665.html

https://cwe.mitre.org/data/definitions/335.html

https://cwe.mitre.org/data/definitions/113.html

https://cwe.mitre.org/data/definitions/113.html

https://cwe.mitre.org/data/definitions/749.html

https://access.redhat.com/errata/RHSA-2020:1268

https://access.redhat.com/security/cve/CVE-2018-1060

https://access.redhat.com/security/cve/CVE-2018-1061

https://access.redhat.com/security/cve/CVE-2018-14647

https://access.redhat.com/security/cve/CVE-2019-9740

https://access.redhat.com/security/cve/CVE-2019-9947

https://access.redhat.com/security/cve/CVE-2019-9948

Plugin Details

Severity: Medium

ID: 135089

File Name: redhat-RHSA-2020-1268.nasl

Version: 1.2

Type: local

Agent: unix

Published: 2020/04/01

Updated: 2020/04/21

Dependencies: 12634

Risk Information

Risk Factor: Medium

CVSS Score Source: CVE-2019-9948

CVSS v2.0

Base Score: 6.4

Temporal Score: 4.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Temporal Vector: CVSS2#E:U/RL:OF/RC:C

CVSS v3.0

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:7.5, cpe:/o:redhat:rhel_eus:7.5, cpe:/o:redhat:rhel_eus:7.5::computenode, cpe:/o:redhat:rhel_eus:7.5::server, p-cpe:/a:redhat:enterprise_linux:python, p-cpe:/a:redhat:enterprise_linux:python-debug, p-cpe:/a:redhat:enterprise_linux:python-devel, p-cpe:/a:redhat:enterprise_linux:python-libs, p-cpe:/a:redhat:enterprise_linux:python-test, p-cpe:/a:redhat:enterprise_linux:python-tools, p-cpe:/a:redhat:enterprise_linux:tkinter

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 2020/04/01

Vulnerability Publication Date: 2018/06/18

Reference Information

CVE: CVE-2018-1060, CVE-2018-1061, CVE-2018-14647, CVE-2019-9740, CVE-2019-9947, CVE-2019-9948

BID: 104495, 104504, 105396, 107466, 107549, 107555

RHSA: 2020:1268

CWE: 20, 113, 335, 665, 749