Important: python3.12-setuptools security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:5533", "synopsis": "Important: python3.12-setuptools security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for python3.12-setuptools.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Setuptools is a collection of enhancements to the Python 3 distutils that allow you to more easily build and distribute Python 3 packages, especially ones that have dependencies on other packages. This package also contains the runtime components of setuptools, necessary to execute the software that requires pkg_resources.\n\nSecurity Fix(es):\n\n* pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools (CVE-2024-6345)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2297771", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2297771", "description": ""}], "cves": [{"name": "CVE-2024-6345", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-6345", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-08-21T14:53:26.062670Z", "rpms": {"Rocky Linux 9": {"nvras": ["python3.12-setuptools-0:68.2.2-3.el9_4.1.noarch.rpm", "python3.12-setuptools-0:68.2.2-3.el9_4.1.src.rpm", "python3.12-setuptools-wheel-0:68.2.2-3.el9_4.1.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Essential python3.12-setuptools patch for Rocky Linux 9 combating vulnerabilities linked to remote code execution threats.. python3 setuptools update, Rocky Linuxsecurity, remote code execution, python package advisory. . Severity: Important. LinuxSecurity.com Team
Update to python3-3.9.2, see https://docs.python.org/3/whatsnew/3.9.html for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-b76ede8f4d 2021-03-15 01:17:22.121076 --------------------------------------------------------------------------------Name : mingw-python3 Product : Fedora 33 Version : 3.9.2 Release : 1.fc33 URL : https://www.python.org/ Summary : MinGW Windows python3 Description : MinGW Windows python3 library. --------------------------------------------------------------------------------Update Information: Update to python3-3.9.2, see https://docs.python.org/3/whatsnew/3.9.html for details. --------------------------------------------------------------------------------ChangeLog: * Mon Feb 22 2021 Sandro Mani - 3.9.2-1 - Update to 3.9.2 * Mon Feb 15 2021 Sandro Mani - 3.9.1-4 - MACHDEP=win32 * Tue Jan 26 2021 Fedora Release Engineering - 3.9.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1928912 - CVE-2021-23336 mingw-python3: python: Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a semicolon in query parameters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1928912 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-b76ede8f4d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.