File _patchinfo of Package patchinfo.33187

<patchinfo incident="33187">
  <issue tracker="bnc" id="1221854">VUL-0: CVE-2024-0450: python: The zipfile module is vulnerable to "quoted-overlap"</issue>
  <issue tracker="bnc" id="1219559">VUL-0: CVE-2023-52425: expat: denial of service (resource consumption) caused by processing large tokens</issue>
  <issue tracker="bnc" id="1219666">VUL-0: CVE-2023-6597: python,python3,python310,python311,python36,python39: tempfile.TemporaryDirectory fails removing dir in some edge cases related to symlinks</issue>
  <issue tracker="bnc" id="1211301">crypto-policies: Extend the crypto-policies support for mozilla-nss, openjdk, krb5, bind, stunnel, openssh, libssh and more packages</issue>
  <issue tracker="bnc" id="1189495">%autopatch missing -m and -M parameter</issue>
  <issue tracker="cve" id="2024-0450"/>
  <issue tracker="cve" id="2023-6597"/>
  <issue tracker="cve" id="2023-52425"/>
  <packager>mcepl</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for python310</summary>
  <description>This update for python310 fixes the following issues:

- CVE-2024-0450: Fixed "quoted-overlap" in zipfile module is python310 (bsc#1221854)
- CVE-2023-52425: Fixed denial of service caused by processing large tokens in expat module in python310 (bsc#1219559)
- CVE-2023-6597: Fixed tempfile.TemporaryDirectory fails on removing dir in some edge cases related to symlinks in python310 (bsc#1219666)
    
    Other changes:

- Revert %autopatch due to missing parameter support (bsc#1189495)
- Extended crypto-policies support (bsc#1211301)

</description>
</patchinfo>
openSUSE Build Service is sponsored by