Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2024:1639-1 — python-aiohttp (CVE-2023-28858 +1 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for python-arcomplete, python-Fabric, python-PyGithub, python-antlr4-python3-runtime, python-avro, python-chardet, python-distro, python-docker, python-fakeredis, python-fixedint, python-httplib2, python-httpretty, python-javaproperties, python-jsondiff, python-knack, python-marshmallow, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-opentelemetry-sdk, python-opentelemetry-semantic-conventions, python-opentelemetry-test-utils, python-pycomposefile, python-pydash, python-redis, python-retrying, python-semver, python-sshtunnel, python-strictyaml, python-sure, python-vcrpy, python-xmltodict

This update for python-argcomplete, python-Fabric, python-PyGithub, python-antlr4-python3-runtime, python-avro, python-chardet, python-distro, python-docker, python-fakeredis, python-fixedint, python-httplib2, python-httpretty, python-javaproperties, python-jsondiff, python-knack, python-marshmallow, python-opencensus, python-opencensus-context, python-opencensus-ext-threading, python-opentelemetry-api, python-opentelemetry-sdk, python-opentelemetry-semantic-conventions, python-opentelemetry-test-utils, python-pycomposefile, python-pydash, python-redis, python-retrying, python-semver, python-sshtunnel, python-strictyaml, python-sure, python-vcrpy, python-xmltodict contains the following fixes:

Changes in python-argcomplete

  • Update to 3.3.0 (bsc#1222880):
  • Preserve compatibility with argparse option tuples of length 4.

This update is required to use argcomplete on Python 3.11.9+ or

3.12.3+.

  • update to 3.2.3:
  • Allow register-python-argcomplete output to be used as lazy-loaded

zsh completion module (#475)

  • Move debug_stream initialization to helper method to allow fd 9

behavior to be overridden in subclasses (#471)

  • update to 3.2.2:
  • Expand tilde in zsh
  • Remove coverage check
  • Fix zsh test failures: avoid coloring terminal
  • update to 3.2.1:
  • Allow explicit zsh global completion activation (#467)
  • Fix and test global completion in zsh (#463, #466)
  • Add –yes option to activate-global-python-argcomplete (#461)
  • Test suite improvements
  • drop without_zsh.patch: obsolete
  • update to 3.1.6:
  • Respect user choice in activate-global-python-argcomplete
  • Escape colon in zsh completions. Fixes #456
  • Call \_default as a fallback in zsh global completion
  • update to 3.1.4:
  • Call \_default as a fallback in zsh global completion
  • zsh: Allow to use external script (#453)
  • Add support for Python 3.12 and drop EOL 3.6 and 3.7 (#449)
  • Use homebrew prefix by default
  • zsh: Allow to use external script (#453)

Changes in python-Fabric:

  • Update to 3.2.2
  • add fix-test-deps.patch to remove vendored dependencies

*[Bug]: fabric.runners.Remote failed to properly deregister its SIGWINCH signal

handler on shutdown; in rare situations this could cause tracebacks when

the Python process receives SIGWINCH while no remote session is active.

This has been fixed.

  • [Bug] #2204: The signal handling functionality added in Fabric 2.6 caused

unrecoverable tracebacks when invoked from inside a thread (such as

the use of fabric.group.ThreadingGroup) under certain interpreter versions.

This has been fixed by simply refusing to register signal handlers when not

in the main thread. Thanks to Francesco Giordano and others for the reports.

  • [Bug]: Neglected to actually add deprecated to our runtime dependency

specification (it was still in our development dependencies). This has been fixed.

  • [Feature]: Enhanced fabric.testing in ways large and small:

Backwards-compatibly merged the functionality of MockSFTP into MockRemote (may be

opted-into by instantiating the latter with enable_sftp=True) so you can mock

out both SSH and SFTP functionality in the same test, which was previously impossible.

It also means you can use this in a Pytest autouse fixture to prevent any tests

from accidentally hitting the network!

A new pytest fixture, remote_with_sftp, has been added which leverages the previous

bullet point (an all-in-one fixture suitable for, eg, preventing any incidental

ssh/sftp attempts during test execution).

A pile of documentation and test enhancements (yes, testing our testing helpers is a thing).

  • [Support]: Added a new runtime dependency on the Deprecated library.
  • [Support]: Language update: applied s/sanity/safety/g to the codebase

(with the few actual API members using the term now marked deprecated & new ones added

in the meantime, mostly in fabric.testing).

  • [Feature]: Add a new CLI flag to fab, fab --list-agent-keys, which will attempt

to connect to your local SSH agent and print a key list, similarly to ssh-add -l.

This is mostly useful for expectations-checking Fabric and Paramiko’s agent

functionality, or for situations where you might not have ssh-add handy.

  • [Feature]: Implement opt-in su

Affected software

SUSE-SU-2024:1639-1 is recorded against 76 packages.

  • python-aiohttp (fixed in 3.9.3-150400.10.18.4)
  • python-aiosignal (fixed in 1.3.1-150400.9.7.2)
  • python-antlr4-python3-runtime (fixed in 4.13.1-150400.10.4.1)
  • python-argcomplete (fixed in 3.3.0-150400.12.12.2)
  • python-asgiref (fixed in 3.6.0-150400.9.7.3)
  • python-async-timeout (fixed in 4.0.2-150400.10.7.2)
  • python-automat (fixed in 22.10.0-150400.3.7.2)
  • python-avro (fixed in 1.11.3-150400.10.4.1)
  • python-blinker (fixed in 1.6.2-150400.12.7.4)
  • python-chardet (fixed in 5.2.0-150400.13.7.2)
  • python-constantly (fixed in 15.1.0-150400.12.7.2)
  • python-decorator (fixed in 5.1.1-150400.12.7.4)
  • python-deprecated (fixed in 1.2.14-150400.10.7.2)
  • python-distro (fixed in 1.9.0-150400.12.4.1)
  • python-docker (fixed in 7.0.0-150400.8.4.4)
  • python-fabric (fixed in 3.2.2-150400.10.4.1)
  • python-fakeredis (fixed in 2.21.0-150400.9.3.4)
  • python-fixedint (fixed in 0.2.0-150400.9.3.1)
  • python-fluidity-sm (fixed in 0.2.0-150400.10.7.2)
  • python-frozenlist (fixed in 1.3.3-150400.9.7.2)
  • python-httplib2 (fixed in 0.22.0-150400.10.4.1)
  • python-httpretty (fixed in 1.1.4-150400.11.4.1)
  • python-humanfriendly (fixed in 10.0-150400.13.7.4)
  • python-hyperlink (fixed in 21.0.0-150400.12.7.4)
Show the remaining 52 packages
  • python-importlib-metadata (fixed in 6.8.0-150400.10.9.2)
  • python-incremental (fixed in 22.10.0-150400.3.7.2)
  • python-invoke (fixed in 2.1.2-150400.10.7.4)
  • python-isodate (fixed in 0.6.1-150400.12.7.2)
  • python-javaproperties (fixed in 0.8.1-150400.10.4.4)
  • python-jsondiff (fixed in 2.0.0-150400.10.4.1)
  • python-knack (fixed in 0.11.0-150400.10.4.4)
  • python-lexicon (fixed in 2.0.1-150400.10.7.1)
  • python-marshmallow (fixed in 3.20.2-150400.9.7.1)
  • python-multidict (fixed in 6.0.4-150400.7.7.4)
  • python-oauthlib (fixed in 3.2.2-150400.12.7.4)
  • python-opencensus (fixed in 0.11.4-150400.10.6.3)
  • python-opencensus-context (fixed in 0.1.3-150400.10.6.1)
  • python-opencensus-ext-threading (fixed in 0.1.2-150400.10.6.1)
  • python-opentelemetry-api (fixed in 1.23.0-150400.10.7.1)
  • python-opentelemetry-sdk (fixed in 1.23.0-150400.9.3.1)
  • python-opentelemetry-semantic-conventions (fixed in 0.44b0-150400.9.3.1)
  • python-opentelemetry-test-utils (fixed in 0.44b0-150400.9.3.1)
  • python-paramiko (fixed in 3.4.0-150400.13.10.4)
  • python-pathspec (fixed in 0.11.1-150400.9.7.2)
  • python-pip (fixed in 22.3.1-150400.17.16.4)
  • python-pkginfo (fixed in 1.9.6-150400.7.7.1)
  • python-portalocker (fixed in 2.7.0-150400.10.7.4)
  • python-psutil (fixed in 5.9.5-150400.6.9.4)
  • python-pycomposefile (fixed in 0.0.30-150400.9.3.1)
  • python-pydash (fixed in 6.0.2-150400.9.4.1)
  • python-pygithub (fixed in 1.57-150400.10.4.4)
  • python-pygments (fixed in 2.15.1-150400.7.7.4)
  • python-pyjwt (fixed in 2.8.0-150400.8.7.2)
  • python-pyparsing (fixed in 3.0.9-150400.5.7.4)
  • python-redis (fixed in 5.0.1-150400.12.4.4)
  • python-requests-oauthlib (fixed in 1.3.1-150400.12.7.1)
  • python-retrying (fixed in 1.3.4-150400.12.4.1)
  • python-scp (fixed in 0.14.5-150400.12.7.4)
  • python-semver (fixed in 3.0.2-150400.10.4.1)
  • python-service-identity (fixed in 23.1.0-150400.8.7.1)
  • python-sortedcontainers (fixed in 2.4.0-150400.8.7.4)
  • python-sshtunnel (fixed in 0.4.0-150400.5.4.4)
  • python-strictyaml (fixed in 1.7.3-150400.9.3.4)
  • python-sure (fixed in 2.0.1-150400.12.4.4)
  • python-tabulate (fixed in 0.9.0-150400.11.7.4)
  • python-tqdm (fixed in 4.66.1-150400.9.7.4)
  • python-twisted (fixed in 22.10.0-150400.5.17.4)
  • python-typing-extensions (fixed in 4.5.0-150400.3.9.1)
  • python-vcrpy (fixed in 6.0.1-150400.7.4.4)
  • python-websocket-client (fixed in 1.5.1-150400.13.7.1)
  • python-wheel (fixed in 0.40.0-150400.13.7.4)
  • python-wrapt (fixed in 1.15.0-150400.12.7.1)
  • python-xmltodict (fixed in 0.13.0-150400.12.4.1)
  • python-yarl (fixed in 1.9.2-150400.8.7.4)
  • python-zipp (fixed in 3.15.0-150400.10.7.1)
  • python-zope.interface (fixed in 6.0-150400.12.7.4)

Timeline and source

Published on 1 July 2024 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2024-07-01
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
python-aiohttp 3.9.3-150400.10.18.4
python-aiosignal 1.3.1-150400.9.7.2
python-antlr4-python3-runtime 4.13.1-150400.10.4.1
python-argcomplete 3.3.0-150400.12.12.2
python-asgiref 3.6.0-150400.9.7.3
python-async-timeout 4.0.2-150400.10.7.2
python-automat 22.10.0-150400.3.7.2
python-avro 1.11.3-150400.10.4.1
python-blinker 1.6.2-150400.12.7.4
python-chardet 5.2.0-150400.13.7.2
python-constantly 15.1.0-150400.12.7.2
python-decorator 5.1.1-150400.12.7.4
python-deprecated 1.2.14-150400.10.7.2
python-distro 1.9.0-150400.12.4.1
python-docker 7.0.0-150400.8.4.4
python-fabric 3.2.2-150400.10.4.1
python-fakeredis 2.21.0-150400.9.3.4
python-fixedint 0.2.0-150400.9.3.1
python-fluidity-sm 0.2.0-150400.10.7.2
python-frozenlist 1.3.3-150400.9.7.2
python-httplib2 0.22.0-150400.10.4.1
python-httpretty 1.1.4-150400.11.4.1
python-humanfriendly 10.0-150400.13.7.4
python-hyperlink 21.0.0-150400.12.7.4
python-importlib-metadata 6.8.0-150400.10.9.2
python-incremental 22.10.0-150400.3.7.2
python-invoke 2.1.2-150400.10.7.4
python-isodate 0.6.1-150400.12.7.2
python-javaproperties 0.8.1-150400.10.4.4
python-jsondiff 2.0.0-150400.10.4.1
python-knack 0.11.0-150400.10.4.4
python-lexicon 2.0.1-150400.10.7.1
python-marshmallow 3.20.2-150400.9.7.1
python-multidict 6.0.4-150400.7.7.4
python-oauthlib 3.2.2-150400.12.7.4
python-opencensus 0.11.4-150400.10.6.3
python-opencensus-context 0.1.3-150400.10.6.1
python-opencensus-ext-threading 0.1.2-150400.10.6.1
python-opentelemetry-api 1.23.0-150400.10.7.1
python-opentelemetry-sdk 1.23.0-150400.9.3.1
python-opentelemetry-semantic-conventions 0.44b0-150400.9.3.1
python-opentelemetry-test-utils 0.44b0-150400.9.3.1
python-paramiko 3.4.0-150400.13.10.4
python-pathspec 0.11.1-150400.9.7.2
python-pip 22.3.1-150400.17.16.4
python-pkginfo 1.9.6-150400.7.7.1
python-portalocker 2.7.0-150400.10.7.4
python-psutil 5.9.5-150400.6.9.4
python-pycomposefile 0.0.30-150400.9.3.1
python-pydash 6.0.2-150400.9.4.1
python-pygithub 1.57-150400.10.4.4
python-pygments 2.15.1-150400.7.7.4
python-pyjwt 2.8.0-150400.8.7.2
python-pyparsing 3.0.9-150400.5.7.4
python-redis 5.0.1-150400.12.4.4
python-requests-oauthlib 1.3.1-150400.12.7.1
python-retrying 1.3.4-150400.12.4.1
python-scp 0.14.5-150400.12.7.4
python-semver 3.0.2-150400.10.4.1
python-service-identity 23.1.0-150400.8.7.1
python-sortedcontainers 2.4.0-150400.8.7.4
python-sshtunnel 0.4.0-150400.5.4.4
python-strictyaml 1.7.3-150400.9.3.4
python-sure 2.0.1-150400.12.4.4
python-tabulate 0.9.0-150400.11.7.4
python-tqdm 4.66.1-150400.9.7.4
python-twisted 22.10.0-150400.5.17.4
python-typing-extensions 4.5.0-150400.3.9.1
python-vcrpy 6.0.1-150400.7.4.4
python-websocket-client 1.5.1-150400.13.7.1
python-wheel 0.40.0-150400.13.7.4
python-wrapt 1.15.0-150400.12.7.1
python-xmltodict 0.13.0-150400.12.4.1
python-yarl 1.9.2-150400.8.7.4
python-zipp 3.15.0-150400.10.7.1
python-zope.interface 6.0-150400.12.7.4

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2024:1639-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2024:1639-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.