stable

python-aiohttp-3.7.4-7.el8

FEDORA-EPEL-2024-bc19d8cc99 created by music 2 weeks ago for Fedora EPEL 8

Security fix for CVE-2024-52304

Update License field to SPDX.

Build and install the C extensions. Based on the history of security fixes in later releases, this may close some vulnerabilities and possibly open others, as both the C and Python HTTP parsing implementations have had their own distinct issues.

While this backports the fix for CVE-2024-52304, and the fix for CVE-2024-23334 was backported in a previous update, it is very likely that other unmitigated issues exist in this old release. Unfortunately, updating to a later version in EPEL8 is impractical at best.

This update has been submitted for testing by music.

2 weeks ago

This update's test gating status has been changed to 'ignored'.

2 weeks ago

This update has been pushed to testing.

2 weeks ago

music edited this update.

2 weeks ago

This update can be pushed to stable now if the maintainer wishes

a week ago

This update has been submitted for stable by bodhi.

2 days ago

This update has been pushed to stable.

2 days ago

Please login to add feedback.

Metadata
Type
security
Severity
low
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
2 weeks ago
in testing
2 weeks ago
in stable
2 days ago
modified
2 weeks ago
approved
a week ago
BZ#2327151 CVE-2024-52304 python-aiohttp: aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions [epel-8]
0
0

Automated Test Results