Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-12349

Опубликовано: 23 мая 2023
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2023-12349: python-pip security update (IMPORTANT)

[9.0.3-8.0.3]

  • CVE-2021-3572 [Orabug: 35240686]

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

python3-pip

9.0.3-8.0.3.el7

Oracle Linux x86_64

python3-pip

9.0.3-8.0.3.el7

Связанные CVE

Связанные уязвимости

CVSS3: 5.7
ubuntu
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 4.5
redhat
около 4 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
nvd
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.

CVSS3: 5.7
msrc
около 3 лет назад

Описание отсутствует

CVSS3: 5.7
debian
больше 3 лет назад

A flaw was found in python-pip in the way it handled Unicode separator ...