File _patchinfo of Package patchinfo.23276

<patchinfo incident="23276">
  <category>security</category>
  <rating>moderate</rating>
  <issue tracker="cve" id="2021-4189"/>
  <issue tracker="cve" id="2022-0391"/>
  <issue tracker="bnc" id="1194146">VUL-0: CVE-2021-4189: python39,python,python36,python3,python27: ftplib should not use the host from the PASV response</issue>
  <issue tracker="bnc" id="1195396">VUL-0: CVE-2022-0391: python3,python27,python,python36,python39: python: urllib.parse does not sanitize URLs containing ASCII newline and tabs</issue>
  <packager>msmeissn</packager>
<issue tracker="bnc" id="1187784">TRACKERBUG: TLS 1.3 enablement for SLES 12 SP5</issue>
<issue tracker="jsc" id="SLE-18105">TLS 1.3 enablement for SLES 12 SP5</issue>
  <summary>Security update for python</summary>
<description>
This update for python rebuilds python against a symbol versioned openssl 1.0.2
to allow usage with openssl 1.1.1.

Also the following security issues are fixed:

- CVE-2022-0391: Fixed sanitizing URLs containing ASCII newline and tabs in urlparse (bsc#1195396).
- CVE-2021-4189: Make ftplib not trust the PASV response (bsc#1194146).
</description>
</patchinfo>
openSUSE Build Service is sponsored by