{
  "schema_version": "1.6.2",
  "id": "MGASA-2021-0193",
  "published": "2021-04-18T18:34:40Z",
  "modified": "2021-04-18T17:36:55Z",
  "summary": "Updated python3 packages fix security vulnerability",
  "details": "There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers\nor is able to convince another local or adjacent user to start a pydoc server\ncould access the server and use it to disclose sensitive information belonging\nto the other user that they would not normally be able to access. The highest\nrisk of this flaw is to data confidentiality (CVE-2021-3426).\n",
  "related": [
    "CVE-2021-3426"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2021-0193.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=28729"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.python.org/issue42988"
    },
    {
      "type": "REPORT",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1935913"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:7",
        "name": "python3",
        "purl": "pkg:rpm/mageia/python3?arch=source&distro=mageia-7"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.7.10-1.1.mga7"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "python3",
        "purl": "pkg:rpm/mageia/python3?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.8.9-1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
