Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-10953

Опубликовано: 12 дек. 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-10953: python36:3.6 security update (IMPORTANT)

python36 python-distro python-docs python-docutils python-nose python-pygments python-pymongo python-PyMySQL python-sqlalchemy python-virtualenv [15.1.0-23]

  • Security fix for CVE-2024-53899 Resolves: RHEL-68876

python-wheel scipy

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module python36:3.6 is enabled

python-nose-docs

1.3.7-31.module+el8.10.0+90473+c30184f9

python-pymongo-doc

3.7.0-1.module+el8.10.0+90473+c30184f9

python-sqlalchemy-doc

1.3.2-3.module+el8.10.0+90473+c30184f9

python-virtualenv-doc

15.1.0-23.module+el8.10.0+90473+c30184f9

python3-PyMySQL

0.10.1-2.module+el8.10.0+90473+c30184f9

python3-bson

3.7.0-1.module+el8.10.0+90473+c30184f9

python3-distro

1.4.0-2.module+el8.10.0+90473+c30184f9

python3-docs

3.6.7-2.module+el8.10.0+90473+c30184f9

python3-docutils

0.14-12.module+el8.10.0+90473+c30184f9

python3-nose

1.3.7-31.module+el8.10.0+90473+c30184f9

python3-pygments

2.2.0-22.module+el8.10.0+90473+c30184f9

python3-pymongo

3.7.0-1.module+el8.10.0+90473+c30184f9

python3-pymongo-gridfs

3.7.0-1.module+el8.10.0+90473+c30184f9

python3-scipy

1.0.0-21.module+el8.10.0+90473+c30184f9

python3-sqlalchemy

1.3.2-3.module+el8.10.0+90473+c30184f9

python3-virtualenv

15.1.0-23.module+el8.10.0+90473+c30184f9

python3-wheel

0.31.1-3.module+el8.10.0+90473+c30184f9

python3-wheel-wheel

0.31.1-3.module+el8.10.0+90473+c30184f9

python36

3.6.8-39.module+el8.10.0+90473+c30184f9

python36-debug

3.6.8-39.module+el8.10.0+90473+c30184f9

python36-devel

3.6.8-39.module+el8.10.0+90473+c30184f9

python36-rpm-macros

3.6.8-39.module+el8.10.0+90473+c30184f9

Oracle Linux x86_64

Module python36:3.6 is enabled

python-nose-docs

1.3.7-31.module+el8.10.0+90473+c30184f9

python-pymongo-doc

3.7.0-1.module+el8.10.0+90473+c30184f9

python-sqlalchemy-doc

1.3.2-3.module+el8.10.0+90473+c30184f9

python-virtualenv-doc

15.1.0-23.module+el8.10.0+90473+c30184f9

python3-PyMySQL

0.10.1-2.module+el8.10.0+90473+c30184f9

python3-bson

3.7.0-1.module+el8.10.0+90473+c30184f9

python3-distro

1.4.0-2.module+el8.10.0+90473+c30184f9

python3-docs

3.6.7-2.module+el8.10.0+90473+c30184f9

python3-docutils

0.14-12.module+el8.10.0+90473+c30184f9

python3-nose

1.3.7-31.module+el8.10.0+90473+c30184f9

python3-pygments

2.2.0-22.module+el8.10.0+90473+c30184f9

python3-pymongo

3.7.0-1.module+el8.10.0+90473+c30184f9

python3-pymongo-gridfs

3.7.0-1.module+el8.10.0+90473+c30184f9

python3-scipy

1.0.0-21.module+el8.10.0+90473+c30184f9

python3-sqlalchemy

1.3.2-3.module+el8.10.0+90473+c30184f9

python3-virtualenv

15.1.0-23.module+el8.10.0+90473+c30184f9

python3-wheel

0.31.1-3.module+el8.10.0+90473+c30184f9

python3-wheel-wheel

0.31.1-3.module+el8.10.0+90473+c30184f9

python36

3.6.8-39.module+el8.10.0+90473+c30184f9

python36-debug

3.6.8-39.module+el8.10.0+90473+c30184f9

python36-devel

3.6.8-39.module+el8.10.0+90473+c30184f9

python36-rpm-macros

3.6.8-39.module+el8.10.0+90473+c30184f9

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
redhat
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
nvd
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activat ...