[issue45072] python 3.9.2 contains ensurepip and pip associates CVE-2021-3572 of pip-20.2.3

2021-08-31 Thread xcl-1


New submission from xcl-1 <1318683...@qq.com>:

python 3.9.2 contains ensurepip and pip associates CVE-2021-3572 of pip-20.2.3

--
messages: 400803
nosy: xcl123
priority: normal
severity: normal
status: open
title: python 3.9.2 contains ensurepip and pip associates CVE-2021-3572 of 
pip-20.2.3

___
Python tracker 
<https://bugs.python.org/issue45072>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue45071] python 3.9.2 contains _bz2.pyd associates CVE-2019-12900 and CVE-2016-3189 of bzip2-1.0.6

2021-08-31 Thread xcl-1


New submission from xcl-1 <1318683...@qq.com>:

python 3.9.2 contains _bz2.pyd associates CVE-2019-12900 and CVE-2016-3189 of 
bzip2-1.0.6

--
messages: 400802
nosy: xcl123
priority: normal
severity: normal
status: open
title: python 3.9.2 contains _bz2.pyd associates CVE-2019-12900 and 
CVE-2016-3189 of bzip2-1.0.6

___
Python tracker 
<https://bugs.python.org/issue45071>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue45070] python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe and wininst-14.0.exe associate

2021-08-31 Thread xcl-1

New submission from xcl-1 <1318683...@qq.com>:

python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. 
wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe 
and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and 
CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5)

--
messages: 400801
nosy: xcl123
priority: normal
severity: normal
status: open
title: python 3.9.2 contains wininst-10.0-amd64.exe. 
wininst-10.0.exe.wininst-7.1.exe. 
wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe 
and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and 
CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5)

___
Python tracker 
<https://bugs.python.org/issue45070>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue45069] python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449 of openssl-1.1.1i

2021-08-31 Thread xcl-1


New submission from xcl-1 <1318683...@qq.com>:

python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates 
CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449
 of openssl-1.1.1i

--
messages: 400800
nosy: xcl123
priority: normal
severity: normal
status: open
title: python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates 
CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449
 of openssl-1.1.1i

___
Python tracker 
<https://bugs.python.org/issue45069>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue45068] python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe and wininst-14.0.exe associate

2021-08-31 Thread xcl-1

xcl-1 <1318683...@qq.com> added the comment:

python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. 
wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe 
and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and 
CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5)

--
title: python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates 
CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449
 of openssl-1.1.1i -> python 3.9.2 contains wininst-10.0-amd64.exe. 
wininst-10.0.exe.wininst-7.1.exe. 
wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe 
and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and 
CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5)

___
Python tracker 
<https://bugs.python.org/issue45068>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com



[issue45068] python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449 of openssl-1.1.1i

2021-08-31 Thread xcl-1


New submission from xcl-1 <1318683...@qq.com>:

Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow 
the output length argument in some cases where the input length is close to the 
maximum permissable length for an integer on the platform. In such cases the 
return value from the function call will be 1 (indicating success), but the 
output length value will be negative. This could cause applications to behave 
incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this 
issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL 
versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is 
out of support and no longer receiving public updates. Premium support 
customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade 
to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 
1.0.2y (Affected 1.0.2-1.0.2x).

--
components: Build
messages: 400798
nosy: xcl123
priority: normal
severity: normal
status: open
title: python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates 
CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449
 of openssl-1.1.1i
type: security

___
Python tracker 
<https://bugs.python.org/issue45068>
___
___
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com