SUSE SLES12: libpython3_4m1_0 / libpython3_4m1_0-32bit / python3 / python3-base / etc (SUSE-SU-2026:3601-1)

high Nessus Plugin ID 335093

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3601-1 advisory.

- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066).
- CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1257599).
- CVE-2026-3219: python-pip: pip doesn't reject concatenated ZIP (bsc#1262467).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959).
- CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442, bsc#1263443).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821).
- CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192).
- Fix for CVE-2026-6019 does not handle non-ascii chars correctly. Regression in `http.cookies` (bsc#1263083).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1257599

https://bugzilla.suse.com/1262467

https://bugzilla.suse.com/1263083

https://bugzilla.suse.com/1263442

https://bugzilla.suse.com/1263443

https://bugzilla.suse.com/1266669

https://bugzilla.suse.com/1267581

https://bugzilla.suse.com/1267821

https://bugzilla.suse.com/1269066

https://bugzilla.suse.com/1269788

https://bugzilla.suse.com/1269959

https://bugzilla.suse.com/1271192

https://www.suse.com/security/cve/CVE-2026-0864

https://www.suse.com/security/cve/CVE-2026-11972

https://www.suse.com/security/cve/CVE-2026-15308

https://www.suse.com/security/cve/CVE-2026-1703

https://www.suse.com/security/cve/CVE-2026-3219

https://www.suse.com/security/cve/CVE-2026-3276

https://www.suse.com/security/cve/CVE-2026-4360

https://www.suse.com/security/cve/CVE-2026-6019

https://www.suse.com/security/cve/CVE-2026-6357

https://www.suse.com/security/cve/CVE-2026-7774

https://www.suse.com/security/cve/CVE-2026-8643

http://www.nessus.org/u?39487993

Plugin Details

Severity: High

ID: 335093

File Name: suse_SU-2026-3601-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/13/2026

Updated: 8/13/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.63

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-6019

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 5.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 7.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-15308

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:libpython3_4m1_0-32bit, p-cpe:/a:novell:suse_linux:libpython3_4m1_0, p-cpe:/a:novell:suse_linux:python3-base, p-cpe:/a:novell:suse_linux:python3-curses, p-cpe:/a:novell:suse_linux:python3-devel, p-cpe:/a:novell:suse_linux:python3-tk, p-cpe:/a:novell:suse_linux:python3

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/12/2026

Vulnerability Publication Date: 2/2/2026

Reference Information

CVE: CVE-2026-0864, CVE-2026-11972, CVE-2026-15308, CVE-2026-1703, CVE-2026-3219, CVE-2026-3276, CVE-2026-4360, CVE-2026-6019, CVE-2026-6357, CVE-2026-7774, CVE-2026-8643

IAVA: 2026-A-0549

SuSE: SUSE-SU-2026:3601-1