Debian Security Advisory
DSA-4307-1 python3.5 -- security update
- Date Reported:
- 28 Sep 2018
- Affected Packages:
- python3.5
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-1000158, CVE-2018-1060, CVE-2018-1061, CVE-2018-14647.
- More information:
-
Multiple security issues were discovered in Python: ElementTree failed to initialise Expat's hash salt, two denial of service issues were found in difflib and poplib and a buffer overflow in PyString_DecodeEscape.
For the stable distribution (stretch), these problems have been fixed in version 3.5.3-1+deb9u1.
We recommend that you upgrade your python3.5 packages.
For the detailed security status of python3.5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python3.5