Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-6324

Опубликовано: 11 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-6324: python3.11-pip security update (MODERATE)

[22.3.1-4]

  • Use tarfile.data_filter for extracting (CVE-2007-4559, PEP-721, PEP-706) Resolves: RHBZ#2218247

[22.3.1-3]

  • Fix changelog to contain Fedora contributors Resolves: RHEL-232

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

python3.11-pip

22.3.1-4.el9

python3.11-pip-wheel

22.3.1-4.el9

Oracle Linux x86_64

python3.11-pip

22.3.1-4.el9

python3.11-pip-wheel

22.3.1-4.el9

Связанные CVE

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 5.5
redhat
почти 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 9.8
nvd
почти 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.

CVSS3: 9.8
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 9.8
debian
почти 18 лет назад

Directory traversal vulnerability in the (1) extract and (2) extractal ...