Debian Security Advisory
DSA-4306-1 python2.7 -- security update
- Date Reported:
- 27 Sep 2018
- Affected Packages:
- python2.7
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-1060, CVE-2018-1061, CVE-2018-14647, CVE-2018-1000802.
- More information:
-
Multiple security issues were discovered in Python: ElementTree failed to initialise Expat's hash salt, two denial of service issues were found in difflib and poplib and the shutil module was affected by a command injection vulnerability.
For the stable distribution (stretch), these problems have been fixed in version 2.7.13-2+deb9u3.
We recommend that you upgrade your python2.7 packages.
For the detailed security status of python2.7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python2.7