Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

SUSE: 2020:3737-1 Moderate: Python-pip, Python-scripttest Security Fix

suse
Calendar Grey December 9, 2020
Dist Suse Esm H88
SUSE Security Patch for issues in python-pip and python-scripttest boosts performance and reliability. Learn more!
An update that solves one vulnerability, contains one feature and has one errata is now available

Summary

This update for python-pip, python-scripttest fixes the following issues: - Update in SLE-15 (bsc#1175297, jsc#ECO-3035, jsc#PM-2318) python-pip was updated to 20.0.2: * Fix a regression in generation of compatibility tags * Rename an internal module, to avoid ImportErrors due to improper uninstallation * Switch to a dedicated CLI tool for vendoring dependencies. * Remove wheel tag calculation from pip and use packaging.tags. This should provide more tags ordered better than in prior releases. * Deprecate setup.py-based builds that do not generate an .egg-info directory. * The pip>=20 wheel cache is not retro-compatible with previous versions. Until pip 21.0, pip will continue to take advantage of existing legacy cache entries. * Deprecate undocumented --skip-requirements-regex option.

References

#1175297 #1176262 ECO-3035

Cross- CVE-2019-20916

Affected Products:

SUSE Linux Enterprise Module for Python2 15-SP2

SUSE Linux Enterprise Module for Python2 15-SP1

SUSE Linux Enterprise Module for Basesystem 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP1

https://www.suse.com/security/cve/CVE-2019-20916.html

https://bugzilla.suse.com/1175297

https://bugzilla.suse.com/1176262

Announcement ID: SUSE-SU-2020:3737-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here