Debian Security Advisory

DSA-4306-1 python2.7 -- security update

Date Reported:
27 Sep 2018
Affected Packages:
python2.7
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-1060, CVE-2018-1061, CVE-2018-14647, CVE-2018-1000802.
More information:

Multiple security issues were discovered in Python: ElementTree failed to initialise Expat's hash salt, two denial of service issues were found in difflib and poplib and the shutil module was affected by a command injection vulnerability.

For the stable distribution (stretch), these problems have been fixed in version 2.7.13-2+deb9u3.

We recommend that you upgrade your python2.7 packages.

For the detailed security status of python2.7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python2.7