<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for python3</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>SUSE-SU-2024:3302-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2024-09-18T12:52:07Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2024-09-18T12:52:07Z</InitialReleaseDate>
    <CurrentReleaseDate>2024-09-18T12:52:07Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for python3</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for python3 fixes the following issues:

- CVE-2024-6923: Fixed uncontrolled CPU resource consumption when in http.cookies module (bsc#1228780).
- CVE-2024-7592: Fixed Email header injection due to unquoted newlines (bsc#1229596)

Bug fixes:

- %{profileopt} variable is set according to the variable %{do_profiling} (bsc#1227999)
- Stop using %%defattr, it seems to be breaking proper executable attributes on /usr/bin/ scripts (bsc#1227378).
- Remove %suse_update_desktop_file macro as it is not useful any more.
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">SUSE-2024-3302,SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-3302,SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-3302,SUSE-SLE-Product-SLES_SAP-15-SP2-2024-3302,SUSE-SUSE-MicroOS-5.1-2024-3302</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20243302-1/</URL>
      <Description>Link for SUSE-SU-2024:3302-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://lists.suse.com/pipermail/sle-updates/2024-September/036953.html</URL>
      <Description>E-Mail link for SUSE-SU-2024:3302-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1227378</URL>
      <Description>SUSE Bug 1227378</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1227999</URL>
      <Description>SUSE Bug 1227999</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1228780</URL>
      <Description>SUSE Bug 1228780</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1229596</URL>
      <Description>SUSE Bug 1229596</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-6923/</URL>
      <Description>SUSE CVE CVE-2024-6923 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2024-7592/</URL>
      <Description>SUSE CVE CVE-2024-7592 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS" CPE="cpe:/o:suse:sle_hpc-ltss:15:sp2">SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Micro 5.1">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Micro 5.1">
        <FullProductName ProductID="SUSE Linux Enterprise Micro 5.1" CPE="cpe:/o:suse:suse-microos:5.1">SUSE Linux Enterprise Micro 5.1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server 15 SP2-LTSS">
        <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS" CPE="cpe:/o:suse:sles-ltss:15:sp2">SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <Branch Type="Product Name" Name="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
        <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2" CPE="cpe:/o:suse:sles_sap:15:sp2">SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libpython3_6m1_0-3.6.15-150000.3.155.2">
      <FullProductName ProductID="libpython3_6m1_0-3.6.15-150000.3.155.2">libpython3_6m1_0-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpython3_6m1_0-32bit-3.6.15-150000.3.155.2">
      <FullProductName ProductID="libpython3_6m1_0-32bit-3.6.15-150000.3.155.2">libpython3_6m1_0-32bit-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpython3_6m1_0-64bit-3.6.15-150000.3.155.2">
      <FullProductName ProductID="libpython3_6m1_0-64bit-3.6.15-150000.3.155.2">libpython3_6m1_0-64bit-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-3.6.15-150000.3.155.2">python3-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-base-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-base-3.6.15-150000.3.155.2">python3-base-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-curses-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-curses-3.6.15-150000.3.155.2">python3-curses-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-dbm-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-dbm-3.6.15-150000.3.155.2">python3-dbm-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-devel-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-devel-3.6.15-150000.3.155.2">python3-devel-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-doc-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-doc-3.6.15-150000.3.155.2">python3-doc-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-doc-devhelp-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-doc-devhelp-3.6.15-150000.3.155.2">python3-doc-devhelp-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-idle-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-idle-3.6.15-150000.3.155.2">python3-idle-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-testsuite-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-testsuite-3.6.15-150000.3.155.2">python3-testsuite-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-tk-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-tk-3.6.15-150000.3.155.2">python3-tk-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-tools-3.6.15-150000.3.155.2">
      <FullProductName ProductID="python3-tools-3.6.15-150000.3.155.2">python3-tools-3.6.15-150000.3.155.2</FullProductName>
    </Branch>
    <Relationship ProductReference="libpython3_6m1_0-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:libpython3_6m1_0-3.6.15-150000.3.155.2">libpython3_6m1_0-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-3.6.15-150000.3.155.2">python3-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-base-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-base-3.6.15-150000.3.155.2">python3-base-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-curses-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-curses-3.6.15-150000.3.155.2">python3-curses-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-dbm-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-dbm-3.6.15-150000.3.155.2">python3-dbm-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-devel-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-devel-3.6.15-150000.3.155.2">python3-devel-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-idle-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-idle-3.6.15-150000.3.155.2">python3-idle-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-tk-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-tk-3.6.15-150000.3.155.2">python3-tk-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-tools-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-tools-3.6.15-150000.3.155.2">python3-tools-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython3_6m1_0-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.1">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.1:libpython3_6m1_0-3.6.15-150000.3.155.2">libpython3_6m1_0-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Micro 5.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.1">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.1:python3-3.6.15-150000.3.155.2">python3-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Micro 5.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-base-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Micro 5.1">
      <FullProductName ProductID="SUSE Linux Enterprise Micro 5.1:python3-base-3.6.15-150000.3.155.2">python3-base-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Micro 5.1</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython3_6m1_0-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:libpython3_6m1_0-3.6.15-150000.3.155.2">libpython3_6m1_0-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-3.6.15-150000.3.155.2">python3-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-base-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-base-3.6.15-150000.3.155.2">python3-base-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-curses-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-curses-3.6.15-150000.3.155.2">python3-curses-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-dbm-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-dbm-3.6.15-150000.3.155.2">python3-dbm-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-devel-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-devel-3.6.15-150000.3.155.2">python3-devel-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-idle-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-idle-3.6.15-150000.3.155.2">python3-idle-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-tk-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-tk-3.6.15-150000.3.155.2">python3-tk-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-tools-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server 15 SP2-LTSS">
      <FullProductName ProductID="SUSE Linux Enterprise Server 15 SP2-LTSS:python3-tools-3.6.15-150000.3.155.2">python3-tools-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server 15 SP2-LTSS</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython3_6m1_0-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:libpython3_6m1_0-3.6.15-150000.3.155.2">libpython3_6m1_0-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-3.6.15-150000.3.155.2">python3-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-base-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-base-3.6.15-150000.3.155.2">python3-base-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-curses-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-curses-3.6.15-150000.3.155.2">python3-curses-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-dbm-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-dbm-3.6.15-150000.3.155.2">python3-dbm-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-devel-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-devel-3.6.15-150000.3.155.2">python3-devel-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-idle-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-idle-3.6.15-150000.3.155.2">python3-idle-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-tk-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-tk-3.6.15-150000.3.155.2">python3-tk-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-tools-3.6.15-150000.3.155.2" RelationType="Default Component Of" RelatesToProductReference="SUSE Linux Enterprise Server for SAP Applications 15 SP2">
      <FullProductName ProductID="SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-tools-3.6.15-150000.3.155.2">python3-tools-3.6.15-150000.3.155.2 as a component of SUSE Linux Enterprise Server for SAP Applications 15 SP2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">There is a MEDIUM severity vulnerability affecting CPython.

The 
email module didn't properly quote newlines for email headers when 
serializing an email message allowing for header injection when an email
 is serialized.</Note>
    </Notes>
    <CVE>CVE-2024-6923</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-curses-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-dbm-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-devel-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-idle-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-tk-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-tools-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.1:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.1:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.1:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-curses-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-dbm-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-devel-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-idle-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-tk-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-tools-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-curses-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-dbm-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-devel-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-idle-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-tk-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-tools-3.6.15-150000.3.155.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20243302-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-6923.html</URL>
        <Description>CVE-2024-6923</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1228780</URL>
        <Description>SUSE Bug 1228780</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">There is a LOW severity vulnerability affecting CPython, specifically the
'http.cookies' standard library module.


When parsing cookies that contained backslashes for quoted characters in
the cookie value, the parser would use an algorithm with quadratic
complexity, resulting in excess CPU resources being used while parsing the
value.</Note>
    </Notes>
    <CVE>CVE-2024-7592</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-curses-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-dbm-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-devel-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-idle-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-tk-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS:python3-tools-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.1:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.1:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Micro 5.1:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-curses-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-dbm-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-devel-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-idle-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-tk-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server 15 SP2-LTSS:python3-tools-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:libpython3_6m1_0-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-base-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-curses-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-dbm-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-devel-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-idle-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-tk-3.6.15-150000.3.155.2</ProductID>
        <ProductID>SUSE Linux Enterprise Server for SAP Applications 15 SP2:python3-tools-3.6.15-150000.3.155.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://www.suse.com/support/update/announcement/2024/suse-su-20243302-1/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2024-7592.html</URL>
        <Description>CVE-2024-7592</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1229596</URL>
        <Description>SUSE Bug 1229596</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
