Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-11048

Опубликовано: 10 янв. 2025
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2024-11048: python-virtualenv security update (IMPORTANT)

[15.1.0-7.0.1]

  • Fixes CVE-2024-53899 Quote template strings in activation scripts [Orabug: 37396464]

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

python-virtualenv

15.1.0-7.0.1.el7_9

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
redhat
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
nvd
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.

CVSS3: 7.8
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 7.8
debian
7 месяцев назад

virtualenv before 20.26.6 allows command injection through the activat ...