<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for python</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2022:1091-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-04-01T14:59:44Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-04-01T14:59:44Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-04-01T14:59:44Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for python</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for python fixes the following issues:

- CVE-2022-0391: Fixed URL sanitization containing ASCII newline and tabs in urlparse (bsc#1195396).
- CVE-2021-4189: Fixed ftplib not to trust the PASV response (bsc#1194146).
- CVE-2021-3572: Fixed an improper handling of unicode characters in pip (bsc#1186819).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-SLE-15.3-2022-1091,openSUSE-SLE-15.4-2022-1091</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULIK4RFHGHTVVWROQ6NTBBB4JWOGWYD6/</URL>
      <Description>E-Mail link for openSUSE-SU-2022:1091-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1175619</URL>
      <Description>SUSE Bug 1175619</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186819</URL>
      <Description>SUSE Bug 1186819</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1194146</URL>
      <Description>SUSE Bug 1194146</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195396</URL>
      <Description>SUSE Bug 1195396</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-3572/</URL>
      <Description>SUSE CVE CVE-2021-3572 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-4189/</URL>
      <Description>SUSE CVE CVE-2021-4189 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0391/</URL>
      <Description>SUSE CVE CVE-2022-0391 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libpython2_7-1_0-2.7.18-150000.38.2">
      <FullProductName ProductID="libpython2_7-1_0-2.7.18-150000.38.2">libpython2_7-1_0-2.7.18-150000.38.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libpython2_7-1_0-32bit-2.7.18-150000.38.2">
      <FullProductName ProductID="libpython2_7-1_0-32bit-2.7.18-150000.38.2">libpython2_7-1_0-32bit-2.7.18-150000.38.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-2.7.18-150000.38.1">
      <FullProductName ProductID="python-2.7.18-150000.38.1">python-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-32bit-2.7.18-150000.38.1">
      <FullProductName ProductID="python-32bit-2.7.18-150000.38.1">python-32bit-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-base-2.7.18-150000.38.2">
      <FullProductName ProductID="python-base-2.7.18-150000.38.2">python-base-2.7.18-150000.38.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-base-32bit-2.7.18-150000.38.2">
      <FullProductName ProductID="python-base-32bit-2.7.18-150000.38.2">python-base-32bit-2.7.18-150000.38.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-curses-2.7.18-150000.38.1">
      <FullProductName ProductID="python-curses-2.7.18-150000.38.1">python-curses-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-demo-2.7.18-150000.38.1">
      <FullProductName ProductID="python-demo-2.7.18-150000.38.1">python-demo-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-devel-2.7.18-150000.38.2">
      <FullProductName ProductID="python-devel-2.7.18-150000.38.2">python-devel-2.7.18-150000.38.2</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-doc-2.7.18-150000.38.1">
      <FullProductName ProductID="python-doc-2.7.18-150000.38.1">python-doc-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-doc-pdf-2.7.18-150000.38.1">
      <FullProductName ProductID="python-doc-pdf-2.7.18-150000.38.1">python-doc-pdf-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-gdbm-2.7.18-150000.38.1">
      <FullProductName ProductID="python-gdbm-2.7.18-150000.38.1">python-gdbm-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-idle-2.7.18-150000.38.1">
      <FullProductName ProductID="python-idle-2.7.18-150000.38.1">python-idle-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-tk-2.7.18-150000.38.1">
      <FullProductName ProductID="python-tk-2.7.18-150000.38.1">python-tk-2.7.18-150000.38.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-xml-2.7.18-150000.38.2">
      <FullProductName ProductID="python-xml-2.7.18-150000.38.2">python-xml-2.7.18-150000.38.2</FullProductName>
    </Branch>
    <Relationship ProductReference="libpython2_7-1_0-2.7.18-150000.38.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpython2_7-1_0-2.7.18-150000.38.2">libpython2_7-1_0-2.7.18-150000.38.2 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libpython2_7-1_0-32bit-2.7.18-150000.38.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libpython2_7-1_0-32bit-2.7.18-150000.38.2">libpython2_7-1_0-32bit-2.7.18-150000.38.2 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-2.7.18-150000.38.1">python-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-32bit-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-32bit-2.7.18-150000.38.1">python-32bit-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-base-2.7.18-150000.38.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-base-2.7.18-150000.38.2">python-base-2.7.18-150000.38.2 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-base-32bit-2.7.18-150000.38.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-base-32bit-2.7.18-150000.38.2">python-base-32bit-2.7.18-150000.38.2 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-curses-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-curses-2.7.18-150000.38.1">python-curses-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-demo-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-demo-2.7.18-150000.38.1">python-demo-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-devel-2.7.18-150000.38.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-devel-2.7.18-150000.38.2">python-devel-2.7.18-150000.38.2 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-doc-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-doc-2.7.18-150000.38.1">python-doc-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-doc-pdf-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-doc-pdf-2.7.18-150000.38.1">python-doc-pdf-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-gdbm-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-gdbm-2.7.18-150000.38.1">python-gdbm-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-idle-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-idle-2.7.18-150000.38.1">python-idle-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-tk-2.7.18-150000.38.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-tk-2.7.18-150000.38.1">python-tk-2.7.18-150000.38.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-xml-2.7.18-150000.38.2" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python-xml-2.7.18-150000.38.2">python-xml-2.7.18-150000.38.2 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.</Note>
    </Notes>
    <CVE>CVE-2021-3572</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libpython2_7-1_0-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:libpython2_7-1_0-32bit-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-32bit-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-base-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-base-32bit-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-curses-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-demo-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-devel-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-doc-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-doc-pdf-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-gdbm-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-idle-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-tk-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-xml-2.7.18-150000.38.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>3.5</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:S/C:N/I:P/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>4.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULIK4RFHGHTVVWROQ6NTBBB4JWOGWYD6/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-3572.html</URL>
        <Description>CVE-2021-3572</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186819</URL>
        <Description>SUSE Bug 1186819</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. This vulnerability could lead to FTP client scanning ports, which otherwise would not have been possible.</Note>
    </Notes>
    <CVE>CVE-2021-4189</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libpython2_7-1_0-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:libpython2_7-1_0-32bit-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-32bit-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-base-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-base-32bit-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-curses-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-demo-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-devel-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-doc-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-doc-pdf-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-gdbm-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-idle-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-tk-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-xml-2.7.18-150000.38.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>5.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULIK4RFHGHTVVWROQ6NTBBB4JWOGWYD6/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-4189.html</URL>
        <Description>CVE-2021-4189</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1194146</URL>
        <Description>SUSE Bug 1194146</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.</Note>
    </Notes>
    <CVE>CVE-2022-0391</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libpython2_7-1_0-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:libpython2_7-1_0-32bit-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-32bit-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-base-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-base-32bit-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-curses-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-demo-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-devel-2.7.18-150000.38.2</ProductID>
        <ProductID>openSUSE Leap 15.3:python-doc-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-doc-pdf-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-gdbm-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-idle-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-tk-2.7.18-150000.38.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python-xml-2.7.18-150000.38.2</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:N/I:P/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ULIK4RFHGHTVVWROQ6NTBBB4JWOGWYD6/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0391.html</URL>
        <Description>CVE-2022-0391</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195396</URL>
        <Description>SUSE Bug 1195396</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
