Improper dependency pinning In python3
Description
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
alpine v3.21 | 3.8.2-r0 | ||
alpine v3.10 | 3.7.7-r0 | ||
alpine v3.18 | 3.8.2-r0 | ||
alpine v3.20 | 3.8.2-r0 | ||
alpine v3.19 | 3.8.2-r0 | ||
alpine v3.15 | 3.8.2-r0 | ||
alpine v3.16 | 3.8.2-r0 | ||
alpine v3.17 | 3.8.2-r0 | ||
alpine v3.22 | 3.8.2-r0 | ||
alpine v3.11 | 3.8.2-r0 |
1-10 of 16
10
Aliases
1. 2. 3. 4. 5. 6.
References
1.