<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for python312</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2024:2572-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-07-22T10:34:49Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-07-22T10:34:49Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-07-22T10:34:49Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for python312</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for python312 fixes the following issues:

- CVE-2024-4032: Corrected information about public and private IPv4
  and IPv6 address ranges (bsc#1226448).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">Container bci/python:latest-2024-2572,SUSE-2024-2572,SUSE-SLE-Module-Python3-15-SP6-2024-2572,openSUSE-SLE-15.6-2024-2572</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20242572-1/</URL>
      <Description>Link for SUSE-SU-2024:2572-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2024-July/036102.html</URL>
      <Description>E-Mail link for SUSE-SU-2024:2572-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1225660</URL>
      <Description>SUSE Bug 1225660</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1226447</URL>
      <Description>SUSE Bug 1226447</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1226448</URL>
      <Description>SUSE Bug 1226448</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1227152</URL>
      <Description>SUSE Bug 1227152</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1227378</URL>
      <Description>SUSE Bug 1227378</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-0397/</URL>
      <Description>SUSE CVE CVE-2024-0397 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-4030/</URL>
      <Description>SUSE CVE CVE-2024-4030 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-4032/</URL>
      <Description>SUSE CVE CVE-2024-4032 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Container bci/python:latest">
      <Branch Type="Product Name" Name="Container bci/python:latest">
        <FullProductName ProductID="Container bci/python:latest">Container bci/python:latest</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Module for Python 3 15 SP6">
        <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6" CPE="cpe:/o:suse:sle-module-python3:15:sp6">SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.6">
      <Branch Type="Product Name" Name="openSUSE Leap 15.6">
        <FullProductName ProductID="openSUSE Leap 15.6" CPE="cpe:/o:opensuse:leap:15.6">openSUSE Leap 15.6</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libpython3_12-1_0-3.12.4-150600.3.3.1">
      <FullProductName ProductID="libpython3_12-1_0-3.12.4-150600.3.3.1">libpython3_12-1_0-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-3.12.4-150600.3.3.1">python312-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-base-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-base-3.12.4-150600.3.3.1">python312-base-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-devel-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-devel-3.12.4-150600.3.3.1">python312-devel-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpython3_12-1_0-32bit-3.12.4-150600.3.3.1">
      <FullProductName ProductID="libpython3_12-1_0-32bit-3.12.4-150600.3.3.1">libpython3_12-1_0-32bit-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpython3_12-1_0-64bit-3.12.4-150600.3.3.1">
      <FullProductName ProductID="libpython3_12-1_0-64bit-3.12.4-150600.3.3.1">libpython3_12-1_0-64bit-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-32bit-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-32bit-3.12.4-150600.3.3.1">python312-32bit-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-64bit-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-64bit-3.12.4-150600.3.3.1">python312-64bit-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-base-32bit-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-base-32bit-3.12.4-150600.3.3.1">python312-base-32bit-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-base-64bit-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-base-64bit-3.12.4-150600.3.3.1">python312-base-64bit-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-curses-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-curses-3.12.4-150600.3.3.1">python312-curses-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-dbm-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-dbm-3.12.4-150600.3.3.1">python312-dbm-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-doc-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-doc-3.12.4-150600.3.3.1">python312-doc-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-doc-devhelp-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-doc-devhelp-3.12.4-150600.3.3.1">python312-doc-devhelp-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-idle-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-idle-3.12.4-150600.3.3.1">python312-idle-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-testsuite-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-testsuite-3.12.4-150600.3.3.1">python312-testsuite-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-tk-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-tk-3.12.4-150600.3.3.1">python312-tk-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python312-tools-3.12.4-150600.3.3.1">
      <FullProductName ProductID="python312-tools-3.12.4-150600.3.3.1">python312-tools-3.12.4-150600.3.3.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libpython3_12-1_0-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="Container bci/python:latest">
      <FullProductName ProductID="Container bci/python:latest:libpython3_12-1_0-3.12.4-150600.3.3.1">libpython3_12-1_0-3.12.4-150600.3.3.1 as a component of Container bci/python:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="Container bci/python:latest">
      <FullProductName ProductID="Container bci/python:latest:python312-3.12.4-150600.3.3.1">python312-3.12.4-150600.3.3.1 as a component of Container bci/python:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-base-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="Container bci/python:latest">
      <FullProductName ProductID="Container bci/python:latest:python312-base-3.12.4-150600.3.3.1">python312-base-3.12.4-150600.3.3.1 as a component of Container bci/python:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-devel-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="Container bci/python:latest">
      <FullProductName ProductID="Container bci/python:latest:python312-devel-3.12.4-150600.3.3.1">python312-devel-3.12.4-150600.3.3.1 as a component of Container bci/python:latest</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython3_12-1_0-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:libpython3_12-1_0-3.12.4-150600.3.3.1">libpython3_12-1_0-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-3.12.4-150600.3.3.1">python312-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-base-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-base-3.12.4-150600.3.3.1">python312-base-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-curses-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-curses-3.12.4-150600.3.3.1">python312-curses-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-dbm-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-dbm-3.12.4-150600.3.3.1">python312-dbm-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-devel-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-devel-3.12.4-150600.3.3.1">python312-devel-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-idle-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-idle-3.12.4-150600.3.3.1">python312-idle-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-tk-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tk-3.12.4-150600.3.3.1">python312-tk-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-tools-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Module for Python 3 15 SP6">
      <FullProductName ProductID="SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tools-3.12.4-150600.3.3.1">python312-tools-3.12.4-150600.3.3.1 as a component of SUSE Linux Enterprise Module for Python 3 15 SP6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython3_12-1_0-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libpython3_12-1_0-3.12.4-150600.3.3.1">libpython3_12-1_0-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython3_12-1_0-32bit-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:libpython3_12-1_0-32bit-3.12.4-150600.3.3.1">libpython3_12-1_0-32bit-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-3.12.4-150600.3.3.1">python312-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-32bit-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-32bit-3.12.4-150600.3.3.1">python312-32bit-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-base-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-base-3.12.4-150600.3.3.1">python312-base-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-base-32bit-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-base-32bit-3.12.4-150600.3.3.1">python312-base-32bit-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-curses-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-curses-3.12.4-150600.3.3.1">python312-curses-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-dbm-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-dbm-3.12.4-150600.3.3.1">python312-dbm-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-devel-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-devel-3.12.4-150600.3.3.1">python312-devel-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-doc-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-doc-3.12.4-150600.3.3.1">python312-doc-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-doc-devhelp-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-doc-devhelp-3.12.4-150600.3.3.1">python312-doc-devhelp-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-idle-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-idle-3.12.4-150600.3.3.1">python312-idle-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-testsuite-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-testsuite-3.12.4-150600.3.3.1">python312-testsuite-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-tk-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-tk-3.12.4-150600.3.3.1">python312-tk-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
    <Relationship ProductReference="python312-tools-3.12.4-150600.3.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.6">
      <FullProductName ProductID="openSUSE Leap 15.6:python312-tools-3.12.4-150600.3.3.1">python312-tools-3.12.4-150600.3.3.1 as a component of openSUSE Leap 15.6</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A defect was discovered in the Python "ssl" module where there is a memory
race condition with the ssl.SSLContext methods "cert_store_stats()" and
"get_ca_certs()". The race condition can be triggered if the methods are
called at the same time as certificates are loaded into the SSLContext,
such as during the TLS handshake with a certificate directory configured.
This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.</Note>
    </Notes>
    <CVE>CVE-2024-0397</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container bci/python:latest:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-curses-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-dbm-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-idle-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tk-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tools-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libpython3_12-1_0-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-base-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-curses-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-dbm-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-doc-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-doc-devhelp-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-idle-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-testsuite-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-tk-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-tools-3.12.4-150600.3.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20242572-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-0397.html</URL>
        <Description>CVE-2024-0397</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226447</URL>
        <Description>SUSE Bug 1226447</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alternate configurations or users without a profile directory may not have the intended permissions.

If you're not using Windows or haven't changed the temporary directory location then you aren't affected by this vulnerability. On other platforms the returned directory is consistently readable and writable only by the current user.

This issue was caused by Python not supporting Unix permissions on Windows. The fix adds support for Unix "700" for the mkdir function on Windows which is used by mkdtemp() to ensure the newly created directory has the proper permissions.</Note>
    </Notes>
    <CVE>CVE-2024-4030</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container bci/python:latest:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-curses-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-dbm-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-idle-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tk-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tools-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libpython3_12-1_0-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-base-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-curses-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-dbm-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-doc-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-doc-devhelp-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-idle-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-testsuite-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-tk-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-tools-3.12.4-150600.3.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20242572-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-4030.html</URL>
        <Description>CVE-2024-4030</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1227152</URL>
        <Description>SUSE Bug 1227152</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">The "ipaddress" module contained incorrect information about whether certain IPv4 and IPv6 addresses were designated as "globally reachable" or "private". This affected the is_private and is_global properties of the ipaddress.IPv4Address, ipaddress.IPv4Network, ipaddress.IPv6Address, and ipaddress.IPv6Network classes, where values wouldn't be returned in accordance with the latest information from the IANA Special-Purpose Address Registries.

CPython 3.12.4 and 3.13.0a6 contain updated information from these registries and thus have the intended behavior.</Note>
    </Notes>
    <CVE>CVE-2024-4032</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>Container bci/python:latest:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>Container bci/python:latest:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-curses-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-dbm-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-idle-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tk-3.12.4-150600.3.3.1</ProductID>
        <ProductID>SUSE Linux Enterprise Module for Python 3 15 SP6:python312-tools-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libpython3_12-1_0-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:libpython3_12-1_0-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-base-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-base-32bit-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-curses-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-dbm-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-devel-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-doc-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-doc-devhelp-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-idle-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-testsuite-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-tk-3.12.4-150600.3.3.1</ProductID>
        <ProductID>openSUSE Leap 15.6:python312-tools-3.12.4-150600.3.3.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20242572-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-4032.html</URL>
        <Description>CVE-2024-4032</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1226448</URL>
        <Description>SUSE Bug 1226448</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
