{"id":"MGASA-2016-0230","summary":"Updated python packages fix security vulnerabilities","details":"Updated python and python3 packages fixes security vulnerability:\n\n- Heap overflow in zipimporter module (CVE-2016-5636).\n- HTTP header injection in urrlib2/urllib/httplib/http.client (CVE-2016-5699).\n- smtplib StartTLS stripping attack (CVE-2016-0772).\n","modified":"2026-04-16T06:24:09.239758492Z","published":"2016-06-22T16:36:39Z","upstream":["CVE-2016-0772","CVE-2016-5636","CVE-2016-5699"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0230.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18691"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/06/16/1"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/06/16/2"},{"type":"WEB","url":"http://openwall.com/lists/oss-security/2016/06/14/9"},{"type":"REPORT","url":"https://bugs.python.org/issue26171"},{"type":"REPORT","url":"https://bugs.python.org/issue5124"},{"type":"REPORT","url":"https://bugs.python.org/issue22928"}],"affected":[{"package":{"name":"python","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/python?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.9-2.3.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0230.json"}},{"package":{"name":"python3","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/python3?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.4.3-1.4.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0230.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}