This issue tracker has been migrated to GitHub, and is currently read-only.
For more information, see the GitHub FAQs in the Python's Developer Guide.

classification
Title: python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449 of openssl-1.1.1i
Type: security Stage: resolved
Components: Build Versions:
process
Status: closed Resolution: out of date
Dependencies: Superseder:
Assigned To: Nosy List: xcl123, zach.ware
Priority: normal Keywords:

Created on 2021-09-01 03:10 by xcl123, last changed 2022-04-11 14:59 by admin. This issue is now closed.

Messages (3)
msg400798 - (view) Author: xcl-1 (xcl123) Date: 2021-09-01 03:10
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output length value will be negative. This could cause applications to behave incorrectly or crash. OpenSSL versions 1.1.1i and below are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1j. OpenSSL versions 1.0.2x and below are affected by this issue. However OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.1.1j (Affected 1.1.1-1.1.1i). Fixed in OpenSSL 1.0.2y (Affected 1.0.2-1.0.2x).
msg400799 - (view) Author: xcl-1 (xcl123) Date: 2021-09-01 03:17
python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5)
msg400804 - (view) Author: Zachary Ware (zach.ware) * (Python committer) Date: 2021-09-01 03:33
v3.9.2 is rather out of date at this point; v3.9.7 was released just yesterday and includes OpenSSL v1.1.1l.  If you're concerned about issues in the version of OpenSSL included with Python v3.9.2, you are encouraged to update to the latest v3.9.7, or replace the OpenSSL DLLs with your own.

The various wininst-*.exe executables are helpers for the deprecated distutils bdist_wininst command, and you are encouraged to not use them :).  You can safely remove them if you do not need bdist_wininst functionality.  They will not be updated.
History
Date User Action Args
2022-04-11 14:59:49adminsetgithub: 89231
2021-09-01 03:33:43zach.waresetstatus: open -> closed

title: python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5) -> python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449 of openssl-1.1.1i
nosy: + zach.ware

messages: + msg400804
resolution: out of date
stage: resolved
2021-09-01 03:17:46xcl123setmessages: + msg400799
title: python 3.9.2 contains libcrypto-1_1.dll and libssl-1_1.dll associates CVE-2021-23840\CVE-2021-3450\CVE-2021-3711\CVE-2021-3712\CVE-2021-23841\CVE-2021-3449 of openssl-1.1.1i -> python 3.9.2 contains wininst-10.0-amd64.exe. wininst-10.0.exe.wininst-7.1.exe. wininst-8.0.exe.wininst-9.0.exe.wininst-9.0-amd64.exe.wininst-14.0-amd64.exe and wininst-14.0.exe associates CVE-2016-9843、CVE-2016-9841、CVE-2016-9840 and CVE-2016-9842 of zlib(1.2.8, 1.2.3,1.2.5)
2021-09-01 03:10:44xcl123create