ELA-265-1 python2.7 security update

fix for infinite loop

2020-08-22
Packagepython2.7
Version2.7.9-2-ds1+deb8u6
Related CVEs CVE-2019-20907


An issue has been found in python2.7, an interactive high-level object-oriented language.

Opening a crafted tar file could result in an infinite loop due to missing header validation.



For Debian 8 jessie, these problems have been fixed in version 2.7.9-2-ds1+deb8u6.

We recommend that you upgrade your python2.7 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.