SUSE SLES15: libpython2_7-1_0 / python / python-base / python-curses / etc (SUSE-SU-2026:3635-1)

high Nessus Plugin ID 337990

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:3635-1 advisory.

- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066).
- CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1257599).
- CVE-2026-3219: python-pip: pip doesn't reject concatenated ZIP (bsc#1262467).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581).
- CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442 bsc#1263443).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash- flooding protection (bsc#1264962).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192).
- Regression in `http.cookies` (bsc#1263083).

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1257599

https://bugzilla.suse.com/1262467

https://bugzilla.suse.com/1263083

https://bugzilla.suse.com/1263442

https://bugzilla.suse.com/1263443

https://bugzilla.suse.com/1264962

https://bugzilla.suse.com/1265268

https://bugzilla.suse.com/1266669

https://bugzilla.suse.com/1267581

https://bugzilla.suse.com/1269066

https://bugzilla.suse.com/1269788

https://bugzilla.suse.com/1271192

https://lists.suse.com/pipermail/sle-updates/2026-August/049368.html

https://www.suse.com/security/cve/CVE-2026-0864

https://www.suse.com/security/cve/CVE-2026-11972

https://www.suse.com/security/cve/CVE-2026-15308

https://www.suse.com/security/cve/CVE-2026-1703

https://www.suse.com/security/cve/CVE-2026-3219

https://www.suse.com/security/cve/CVE-2026-3276

https://www.suse.com/security/cve/CVE-2026-6357

https://www.suse.com/security/cve/CVE-2026-7210

https://www.suse.com/security/cve/CVE-2026-8328

https://www.suse.com/security/cve/CVE-2026-8643

Plugin Details

Severity: High

ID: 337990

File Name: suse_SU-2026-3635-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 8/19/2026

Updated: 8/19/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.63

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2026-8643

CVSS v3

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-15308

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:15, p-cpe:/a:novell:suse_linux:libpython2_7-1_0, p-cpe:/a:novell:suse_linux:python-base, p-cpe:/a:novell:suse_linux:python-curses, p-cpe:/a:novell:suse_linux:python-gdbm, p-cpe:/a:novell:suse_linux:python-xml, p-cpe:/a:novell:suse_linux:python

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 8/18/2026

Vulnerability Publication Date: 2/2/2026

Reference Information

CVE: CVE-2026-0864, CVE-2026-11972, CVE-2026-15308, CVE-2026-1703, CVE-2026-3219, CVE-2026-3276, CVE-2026-6357, CVE-2026-7210, CVE-2026-8328, CVE-2026-8643

IAVA: 2026-A-0549

SuSE: SUSE-SU-2026:3635-1