This issue tracker has been migrated to GitHub, and is currently read-only.
For more information, see the GitHub FAQs in the Python's Developer Guide.

classification
Title: Why Does 3rd/Python39/Lib/site-packages/psycopg2/_psycopg.cp39-win_amd64.pyd Have the CVE-2021-3711 CVE-2021-23840 CVE-2021-3450 CVE-2021-3712 CVE-2021-23841 CVE-2021-3449 CVE-2021-4160 Vulnerability? I Use Python 3.9.2? Where Is OpenSSL Used?
Type: security Stage: resolved
Components: Library (Lib) Versions: Python 3.9
process
Status: closed Resolution: third party
Dependencies: Superseder:
Assigned To: Nosy List: zach.ware, zjmxq
Priority: normal Keywords:

Created on 2022-02-19 06:59 by zjmxq, last changed 2022-04-11 14:59 by admin. This issue is now closed.

Messages (1)
msg413552 - (view) Author: Zachary Ware (zach.ware) * (Python committer) Date: 2022-02-19 15:09
Psycopg2 is a third-party package; questions about it should be directed to the Users category of discuss.python.org, the python-list mailing list, or a forum specific to psycopg2.

Also, note that Python 3.9.2 is well out of date; you should update to 3.9.10 or 3.10.2.  On Windows, OpenSSL is included with Python, and is most easily updated by updating Python.

And lastly, please use the comment field rather than cramming your comments into the title field.
History
Date User Action Args
2022-04-11 14:59:56adminsetgithub: 90951
2022-02-19 15:09:28zach.waresetstatus: open -> closed

nosy: + zach.ware
messages: + msg413552

resolution: third party
stage: resolved
2022-02-19 08:37:07zjmxqsettitle: Why Does 3rd/Python39/Lib/site-packages/psycopg2/_psycopg.cp39-win_amd64.pyd Have the CVE-20211-4160 Vulnerability? I Use Python 3.9.2? Where Is OpenSSL Used? -> Why Does 3rd/Python39/Lib/site-packages/psycopg2/_psycopg.cp39-win_amd64.pyd Have the CVE-2021-3711 CVE-2021-23840 CVE-2021-3450 CVE-2021-3712 CVE-2021-23841 CVE-2021-3449 CVE-2021-4160 Vulnerability? I Use Python 3.9.2? Where Is OpenSSL Used?
2022-02-19 07:01:08zjmxqsettitle: Why does 3rd/Python39/Lib/site-packages/psycopg2/_psycopg.cp39-win_amd64.pyd have the CVE-201-4160 vulnerability when I use Python 3.9.2 -> Why Does 3rd/Python39/Lib/site-packages/psycopg2/_psycopg.cp39-win_amd64.pyd Have the CVE-20211-4160 Vulnerability? I Use Python 3.9.2? Where Is OpenSSL Used?
2022-02-19 06:59:26zjmxqcreate