Debian dla-4827 : idle-python3.11 - 安全性更新

critical Nessus Plugin ID 364182

概要

遠端 Debian 主機上缺少一個或多個安全性更新。

說明

遠端 Debian 12 主機已安裝的套件會受到 dla-4827 公告中提及的多個弱點影響。

- ------------------------------------------------------------------------- Debian LTS 公告 DLA-4827-1 [email protected] https://www.debian.org/lts/security/Andrej Shadura 2026 年 10 月 8 日 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

套件 : python3.11 版本 : 3.11.2-6+deb12u9 CVE ID : CVE-2025-69534 CVE-2026-1502 CVE-2026-3276 CVE-2026-6019 CVE-2026-8328 CVE-2026-9669 CVE-2026-15308 CVE-2026-15310 CVE-2026-15806 CVE-2026-17084 CVE-2026-18503 CVE-2026-19445 CVE-2026-19553 Debian 錯誤 : 1131896

Python 3.11中的多個漏洞。

CVE-2025-69534

格式錯誤的標記宣告可能會使 html.parser.HTMLParser 引發未處理的 AssertionError。剖析不受信任 HTML 的應用程式 (例如 Python-Markdown 轉譯不受信任的輸入) 可能會當機,進而導致拒絕服務。

CVE-2026-1502

http.client 未拒絕代理通道主機或通道要求標頭中的 CR/LF 位元組,這可能會允許 HTTP 標頭插入。

CVE-2026-3276

unicodedata.normalize() 在處理特製的 Unicode 輸入時,可能會佔用過多的 CPU 時間,其中包含長時間的組合字元與交替的標準組合類別值。這會影響所有正規化形式。

CVE-2026-6019

http.cookies.Morsel.js_output() 傳回一個內嵌 <script> 程式碼片段,其中 cookie 值僅針對 JavaScript 字串內容逸出,而不會中和 </script> 序列,因此攻擊者控制的 cookie 值可以將標記插入頁面。

CVE-2026-8328

修正時 CVE-2021-4189 未更新 ftplib.ftpcp(),但仍會將來源伺服器傳回的 PASV 位址傳遞至目標伺服器。惡意來源 FTP 伺服器可以使用此功能將目標伺服器的資料連線導向至任意主機和連接埠。

CVE-2026-9669

bz2。BZ2Decompressor 物件可以在解壓縮錯誤之後重複使用。如果應用程式擷取產生的 OSError 並使用相同的解壓縮器重試,則特製的輸入可能會導致堆疊緩衝區越界寫入,進程當機。

CVE-2026-15308

以增量方式向 html.parser.HTMLParser 提供長而未終止的結構 (例如標籤或註解) 需要二次時間,從而允許透過 CPU 耗盡而造成拒絕服務。

CVE-2026-15310

當使用 bzip2 或 LZMA 壓縮解壓縮特製的 zip 檔案時,zipfile 可以使用攻擊者控制的大小來預先配置內存,從而可能導致記憶體耗盡。

CVE-2026-15806

urllib.request.HTTPPasswordMgr 及其子類別在比對已儲存的憑證時未考慮 URL 配置。
為 https:// URL 新增的憑證也會透過 http:// 傳送至相同的主機,因此能夠將用戶端重新導向或降級為純HTTP的攻擊者可以以純文字形式擷取它們。

CVE-2026-17084

stringprep 模組在檢查表格 B.2 和 B.3 時,使用當前的 Unicode 程式碼點屬性,而不是 RFC 3454 的要求 Unicode 3.2.0的屬性。在處理具有 IDNA 2003 (idna) 編解碼器的網域名稱時,這可能會導致不相符。

CVE-2026-18503

攻擊者控制的 CSV 範例可觸發 CSV 中的超線性規則運算式比對。Sniffer.sniff(),佔用大量 CPU 時間。

CVE-2026-19445

如果伺服器的sni_callback將不同的內容指派給 SSLSocket.context,而且沒有其他內容保留原始 SSL,則遠端未經驗證的 TLS 用戶端可能會使伺服器當機或透過釋放的指標呼叫。SSLContext 處於活動狀態。


CVE-2026-19553

ssl。啟用 check_hostname 時,SSLContext.wrap_bio() 不需要 server_hostname 引數,因此可以無訊息地跳過主機名稱驗證;asyncio 的 create_connection() 和 loop.start_tls() 也受到影響。為了相容性,Python 3.11 現在在這種情況下會發出 DeprecationWarning,而不是引發 ValueError,因此應用程式仍然需要傳遞有效的server_hostname。

對於 Debian 12 書蟲,這些問題已在 3.11.2-6+deb12u9 版本中修復。

此外,此更新還包含下列相關的上游修正:

* csv。Sniffer.sniff() 在偵測雙引號時,在具有許多引號字元的樣本上可能需要指數時間 (gh-109638)。

* 當重複的子模式包含回溯時,具有所有格量詞的規則運算式可能會給出錯誤的比對 (gh-100061、gh-106052)。

* html.parser.HTMLParser 未根據 HTML5 標準剖析開始和結束標籤,並且在未關閉的指令碼或樣式標籤 (GH-135661、GH-86155) 後可能會遺失資料。修正後,某些格式錯誤的標記會以不同的方式剖析;例如, </ script> 不再結束指令碼元素。

建議您升級 python3.11 套件。

如需 python3.11 的詳細安全性狀態,請參閱其安全追蹤頁面:
https://security-tracker.debian.org/tracker/python3.11

有關 Debian LTS 安全公告、如何將這些更新套用至您的系統以及常見問題的詳細資訊,請參閱 : https://wiki.debian.org/LTS

Tenable 已直接從 Debian 安全公告擷取前置描述區塊。

請注意,Nessus 並未測試這些問題,而是僅依據應用程式自我報告的版本號碼作出判斷。

解決方案

升級 idle-python3.11 套件。

另請參閱

https://packages.debian.org/source/bookworm/python3.11

https://security-tracker.debian.org/tracker/CVE-2021-4189

https://security-tracker.debian.org/tracker/CVE-2025-69534

https://security-tracker.debian.org/tracker/CVE-2026-1502

https://security-tracker.debian.org/tracker/CVE-2026-15308

https://security-tracker.debian.org/tracker/CVE-2026-15310

https://security-tracker.debian.org/tracker/CVE-2026-15806

https://security-tracker.debian.org/tracker/CVE-2026-17084

https://security-tracker.debian.org/tracker/CVE-2026-18503

https://security-tracker.debian.org/tracker/CVE-2026-19445

https://security-tracker.debian.org/tracker/CVE-2026-19553

https://security-tracker.debian.org/tracker/CVE-2026-3276

https://security-tracker.debian.org/tracker/CVE-2026-6019

https://security-tracker.debian.org/tracker/CVE-2026-8328

https://security-tracker.debian.org/tracker/CVE-2026-9669

https://security-tracker.debian.org/tracker/source-package/python3.11

Plugin 詳細資訊

嚴重性: Critical

ID: 364182

檔案名稱: debian_DLA-4827.nasl

版本: 1.1

類型: Local

代理程式: unix

已發布: 2026/10/8

已更新: 2026/10/8

支援的感應器: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

風險資訊

VPR

風險因素: Medium

分數: 6.3

百分位數: 96.3

CVSS v2

風險因素: Medium

基本分數: 6.4

時間性分數: 5

媒介: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS 評分資料來源: CVE-2026-6019

CVSS v3

風險因素: Medium

基本分數: 6.1

時間性分數: 5.5

媒介: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

時間媒介: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

風險因素: Critical

Base Score: 9.2

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N

CVSS 評分資料來源: CVE-2026-19445

弱點資訊

CPE: cpe:/o:debian:debian_linux:12.0, p-cpe:/a:debian:debian_linux:idle-python3.11, p-cpe:/a:debian:debian_linux:libpython3.11-dbg, p-cpe:/a:debian:debian_linux:libpython3.11-dev, p-cpe:/a:debian:debian_linux:libpython3.11-minimal, p-cpe:/a:debian:debian_linux:libpython3.11-stdlib, p-cpe:/a:debian:debian_linux:libpython3.11-testsuite, p-cpe:/a:debian:debian_linux:libpython3.11, p-cpe:/a:debian:debian_linux:python3.11-dbg, p-cpe:/a:debian:debian_linux:python3.11-dev, p-cpe:/a:debian:debian_linux:python3.11-doc, p-cpe:/a:debian:debian_linux:python3.11-examples, p-cpe:/a:debian:debian_linux:python3.11-full, p-cpe:/a:debian:debian_linux:python3.11-minimal, p-cpe:/a:debian:debian_linux:python3.11-nopie, p-cpe:/a:debian:debian_linux:python3.11-venv, p-cpe:/a:debian:debian_linux:python3.11

必要的 KB 項目: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

可被惡意程式利用: true

可輕鬆利用: Exploits are available

修補程式發佈日期: 2026/10/8

弱點發布日期: 2021/8/24

參考資訊

CVE: CVE-2021-4189, CVE-2025-69534, CVE-2026-1502, CVE-2026-15308, CVE-2026-15310, CVE-2026-15806, CVE-2026-17084, CVE-2026-18503, CVE-2026-19445, CVE-2026-19553, CVE-2026-3276, CVE-2026-6019, CVE-2026-8328, CVE-2026-9669