RHEL 9 : python3.12 (RHSA-2024:9190)

high Nessus Plugin ID 210811

Synopsis

The remote Red Hat host is missing one or more security updates for python3.12.

Description

The remote Redhat Enterprise Linux 9 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2024:9190 advisory.

Python 3.12 is an accessible, high-level, dynamically typed, interpreted programming language, designed with an emphasis on code readability. It includes an extensive standard library, and has a vast ecosystem of third-party libraries. The python3.12 package provides the python3.12 executable: the reference interpreter for the Python language, version 3. The majority of its standard library is provided in the python3.12-libs package, which should be installed automatically along with python3.12. The remaining parts of the Python standard library are broken out into the python3.12-tkinter and python3.12-test packages, which may need to be installed separately. Documentation for Python is provided in the python3.12-docs package. Packages containing additional libraries for Python are generally named with the python3.12- prefix.

Security Fix(es):

* python: The zipfile module is vulnerable to zip-bombs leading to denial of service (CVE-2024-0450)

* python: incorrect IPv4 and IPv6 private ranges (CVE-2024-4032)

* python: cpython: Iterating over a malicious ZIP file may lead to Denial of Service (CVE-2024-8088)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL python3.12 package based on the guidance in RHSA-2024:9190.

See Also

https://access.redhat.com/security/updates/classification/#moderate

https://bugzilla.redhat.com/show_bug.cgi?id=2276525

https://bugzilla.redhat.com/show_bug.cgi?id=2292921

https://bugzilla.redhat.com/show_bug.cgi?id=2307370

http://www.nessus.org/u?bb08292d

http://www.nessus.org/u?acf194f3

https://access.redhat.com/errata/RHSA-2024:9190

Plugin Details

Severity: High

ID: 210811

File Name: redhat-RHSA-2024-9190.nasl

Version: 1.1

Type: local

Agent: unix

Published: 11/12/2024

Updated: 11/12/2024

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2024-4032

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.6

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2024-8088

Vulnerability Information

CPE: cpe:/o:redhat:enterprise_linux:9, p-cpe:/a:redhat:enterprise_linux:python3.12, p-cpe:/a:redhat:enterprise_linux:python3.12-debug, p-cpe:/a:redhat:enterprise_linux:python3.12-devel, p-cpe:/a:redhat:enterprise_linux:python3.12-idle, p-cpe:/a:redhat:enterprise_linux:python3.12-libs, p-cpe:/a:redhat:enterprise_linux:python3.12-test, p-cpe:/a:redhat:enterprise_linux:python3.12-tkinter

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 11/12/2024

Vulnerability Publication Date: 3/19/2024

Reference Information

CVE: CVE-2024-0450, CVE-2024-4032, CVE-2024-8088

CWE: 440, 450, 835

RHSA: 2024:9190