Format: 1.8 Date: Thu, 09 Dec 2021 12:53:27 -0500 Source: python3.8 Binary: python3.8 python3.8-venv libpython3.8-stdlib python3.8-minimal libpython3.8-minimal libpython3.8 python3.8-examples python3.8-dev libpython3.8-dev libpython3.8-testsuite idle-python3.8 python3.8-doc python3.8-dbg libpython3.8-dbg Architecture: arm64 Version: 3.8.0-3ubuntu1~18.04.2 Distribution: bionic Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Ian Constantin Description: idle-python3.8 - IDE for Python (v3.8) using Tkinter libpython3.8 - Shared Python runtime library (version 3.8) libpython3.8-dbg - Debug Build of the Python Interpreter (version 3.8) libpython3.8-dev - Header files and a static library for Python (v3.8) libpython3.8-minimal - Minimal subset of the Python language (version 3.8) libpython3.8-stdlib - Interactive high-level object-oriented language (standard library libpython3.8-testsuite - Testsuite for the Python standard library (v3.8) python3.8 - Interactive high-level object-oriented language (version 3.8) python3.8-dbg - Debug Build of the Python Interpreter (version 3.8) python3.8-dev - Header files and a static library for Python (v3.8) python3.8-doc - Documentation for the high-level object-oriented language Python python3.8-examples - Examples for the Python language (v3.8) python3.8-minimal - Minimal subset of the Python language (version 3.8) python3.8-venv - Interactive high-level object-oriented language (pyvenv binary, v Changes: python3.8 (3.8.0-3ubuntu1~18.04.2) bionic-security; urgency=medium . * SECURITY UPDATE: Regular Expression Denial of Service - debian/patches/CVE-2020-8492.patch: updates a regular expression in the urllib.request.AbsatrctBasicAuthHandler class which allows for catastrophic backtracking and could result in a Denial of Service condition. - CVE-2020-8492 * SECURITY UPDATE: Regular Expression Denial of Service - debian/patches/CVE-2021-3733.patch: updates a regular expression in the urllib.request.AbstractBasicAuthHandler class which has a quadratic worst-case time complexity and could be abused by a malicious HTTP server to cause a Denial of Service condition for a client. - CVE-2021-3733 * SECURITY UPDATE: Denial of Service - debian/patches/CVE-2021-3737.patch: addresses the potential for the urllib http client to enter into an infinite loop and hang on a 100 Continue response from a malicious server. - debian/patches/CVE-2021-3737_test-fix.patch: improves the regression test in Lib/test/test_httplib.py - CVE-2021-3737 Checksums-Sha1: bbc85f98dc0c535ea48c996c1d3f6c0884758985 12948844 libpython3.8-dbg_3.8.0-3ubuntu1~18.04.2_arm64.deb ecbbf3e2468001289f749ace929f511f3acb8ef8 54240220 libpython3.8-dev_3.8.0-3ubuntu1~18.04.2_arm64.deb 3ccba0eafa02ce29b810e243f7b1661dd41f7407 702128 libpython3.8-minimal_3.8.0-3ubuntu1~18.04.2_arm64.deb a28b8fae5ebece2a24c88ae743fcb3e6a1a4fae7 1649144 libpython3.8-stdlib_3.8.0-3ubuntu1~18.04.2_arm64.deb 66705bd884b591095c975e1706c835bdb4794f91 1495712 libpython3.8_3.8.0-3ubuntu1~18.04.2_arm64.deb c89cf1ae98603721556fa4a48c626b11fe2e12b0 18377356 python3.8-dbg_3.8.0-3ubuntu1~18.04.2_arm64.deb 5cf8b2d0ad475ae9ebe27a0aba5d64f9db0e6908 510864 python3.8-dev_3.8.0-3ubuntu1~18.04.2_arm64.deb b92c80fd5164c8141cff76c9fe0580568cf3be73 1730400 python3.8-minimal_3.8.0-3ubuntu1~18.04.2_arm64.deb 0c13fbec0846131eda2f4ad9c6927ce89656cf58 5304 python3.8-venv_3.8.0-3ubuntu1~18.04.2_arm64.deb 716be96d68e79f50e5378037d3cbfdb8bbb38a66 12934 python3.8_3.8.0-3ubuntu1~18.04.2_arm64.buildinfo d816d71e332f57c0bf3235738141c0ee23867c6d 354840 python3.8_3.8.0-3ubuntu1~18.04.2_arm64.deb Checksums-Sha256: c8af77807580158e135b5ceb636ed2a01f8fc2200ec2242f17013f77fe8e8868 12948844 libpython3.8-dbg_3.8.0-3ubuntu1~18.04.2_arm64.deb 0f7f6a3af66201fe1185ea23a3ebad21f60e002d2b81fbac22391b8b688dcc1c 54240220 libpython3.8-dev_3.8.0-3ubuntu1~18.04.2_arm64.deb 3d878b10e792909f23a741a741df61139317ad9f0bf58ffd0055ec82bd64e9d9 702128 libpython3.8-minimal_3.8.0-3ubuntu1~18.04.2_arm64.deb afd0ff6100917d298c9465ab44616849c859553e7a6fa6e10a0809912e20b4f8 1649144 libpython3.8-stdlib_3.8.0-3ubuntu1~18.04.2_arm64.deb c932563ea0577cd17db4bf8660cd8b3e576ea024dd8b2fd3d6cd4e528bc23944 1495712 libpython3.8_3.8.0-3ubuntu1~18.04.2_arm64.deb 7d6768c6cfd34a2652ea6db85c65baa79d22202f22b48617fbe14884a471c24c 18377356 python3.8-dbg_3.8.0-3ubuntu1~18.04.2_arm64.deb 49d11df7f9630ff3eb6f5043699bf24c47650e665d27ff597a8240d06968d8c7 510864 python3.8-dev_3.8.0-3ubuntu1~18.04.2_arm64.deb 28ed1e1ec923643abc170b29dc863a57fb6f1f36e5f4e114bb67a8aac1aa3a95 1730400 python3.8-minimal_3.8.0-3ubuntu1~18.04.2_arm64.deb e721fa4cd57aec694a44fb5eac97f496d07b267dadc392477e6522fdf29b6794 5304 python3.8-venv_3.8.0-3ubuntu1~18.04.2_arm64.deb 7bcfbdeedb33a61d4357a318b73f1dd25b0af8fed6252d93bb45231ed7a5e178 12934 python3.8_3.8.0-3ubuntu1~18.04.2_arm64.buildinfo 2cbf62aafec75021be0e465aec38090a7411a35f1f50354c0e9b2f634ebf219c 354840 python3.8_3.8.0-3ubuntu1~18.04.2_arm64.deb Files: d5a7c436a188f3fdf0a225d165a43811 12948844 debug optional libpython3.8-dbg_3.8.0-3ubuntu1~18.04.2_arm64.deb 3197292dda76a4a0c2faab60b5ef3de3 54240220 libdevel optional libpython3.8-dev_3.8.0-3ubuntu1~18.04.2_arm64.deb 63c851a2993cb66f4dd2ec383873cf68 702128 python optional libpython3.8-minimal_3.8.0-3ubuntu1~18.04.2_arm64.deb 293a7df2103803d5336e83bc87aec357 1649144 python optional libpython3.8-stdlib_3.8.0-3ubuntu1~18.04.2_arm64.deb 418ee1ca37142d26562b6322451ca3e1 1495712 libs optional libpython3.8_3.8.0-3ubuntu1~18.04.2_arm64.deb 375414b6f64dfabbffe5939c1896f4f7 18377356 debug optional python3.8-dbg_3.8.0-3ubuntu1~18.04.2_arm64.deb c66423921020c8f5870d5d966b14d386 510864 python optional python3.8-dev_3.8.0-3ubuntu1~18.04.2_arm64.deb a87dfb688e41001edf43096657d13f40 1730400 python optional python3.8-minimal_3.8.0-3ubuntu1~18.04.2_arm64.deb 808487f881e65a34dff22462c487f773 5304 python optional python3.8-venv_3.8.0-3ubuntu1~18.04.2_arm64.deb 17fab9ffcbc8b5191a91831443f5540c 12934 python optional python3.8_3.8.0-3ubuntu1~18.04.2_arm64.buildinfo 2c5061b3edf19e47a70f2a1d7dc7705a 354840 python optional python3.8_3.8.0-3ubuntu1~18.04.2_arm64.deb Original-Maintainer: Matthias Klose