<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE1-SA-2025-0007</id>
    <title>An update for python3 is now available for HCE 1.1</title>
    <severity>Critical</severity>
    <release>HCE 1.1</release>
    <issued date="2025-03-21 03:30:25"/>
    <updated date="2025-03-21 03:30:25"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2021-3177" id="CVE-2021-3177" title="CVE-2021-3177 Base Score: 9.8 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2024-6232" id="CVE-2024-6232" title="CVE-2024-6232 Base Score: 7.5 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2021-3426" id="CVE-2021-3426" title="CVE-2021-3426 Base Score: 5.7 Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" type="cve"/>
    </references>
    <description>Security Fix(es):

Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demonstrated by a 1e300 argument to c_double.from_param. This occurs because sprintf is used unsafely. (CVE-2021-3177)

There is a MEDIUM severity vulnerability affecting CPython.





Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives. (CVE-2024-6232)

There_x27;s a flaw in Python 3_x27;s pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk of this flaw is to data confidentiality. This flaw affects Python versions before 3.8.9, Python versions before 3.9.3 and Python versions before 3.10.0a7. (CVE-2021-3426)
</description>
    <pkglist>
      <collection short="HCE 1.1" package="python3">
        <name>HCE 1.1</name>
        <package arch="x86_64" name="python3" version="3.6.8" release="22.hce1c">
          <filename>python3-3.6.8-22.hce1c.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="python3-libs" version="3.6.8" release="22.hce1c">
          <filename>python3-libs-3.6.8-22.hce1c.x86_64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
