File _patchinfo of Package patchinfo.33053

<patchinfo incident="33053">
  <issue tracker="cve" id="2023-6597"/>
  <issue tracker="cve" id="2024-0450"/>
  <issue tracker="cve" id="2023-52425"/>
  <issue tracker="bnc" id="1219559">VUL-0: CVE-2023-52425: expat: denial of service (resource consumption) caused by processing large tokens</issue>
  <issue tracker="bnc" id="1219666">VUL-0: CVE-2023-6597: python,python3,python310,python311,python36,python39: tempfile.TemporaryDirectory fails removing dir in some edge cases related to symlinks</issue>
  <issue tracker="bnc" id="1211301">crypto-policies: Extend the crypto-policies support for mozilla-nss, openjdk, krb5, bind, stunnel, openssh, libssh and more packages</issue>
  <issue tracker="bnc" id="1221854">VUL-0: CVE-2024-0450: python: The zipfile module is vulnerable to "quoted-overlap"</issue>
  <packager>mcepl</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for python39</summary>
  <description>This update for python39 fixes the following issues:

- CVE-2023-52425: Fixed denial of service (resource consumption) caused by processing large tokens in expat (bsc#1219559).
- CVE-2023-6597: Fixed symlink race condition in tempfile.TemporaryDirectory (bsc#1219666).
- CVE-2024-0450: Fixed "quoted-overlap" in zipfile module (bsc#1221854).

The following non-security bugs were fixed:

- Use the system-wide crypto-policies (bsc#1211301).
</description>
</patchinfo>
openSUSE Build Service is sponsored by