Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-5533

Опубликовано: 19 авг. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-5533: python3.12-setuptools security update (IMPORTANT)

[68.2.2-3.1]

  • Security fix for CVE-2024-6345 Resolves: RHEL-50481

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

python3.12-setuptools

68.2.2-3.el9_4.1

python3.12-setuptools-wheel

68.2.2-3.el9_4.1

Oracle Linux x86_64

python3.12-setuptools

68.2.2-3.el9_4.1

python3.12-setuptools-wheel

68.2.2-3.el9_4.1

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
11 месяцев назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
redhat
11 месяцев назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
nvd
11 месяцев назад

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

CVSS3: 8.8
msrc
8 месяцев назад

Описание отсутствует

CVSS3: 8.8
debian
11 месяцев назад

A vulnerability in the package_index module of pypa/setuptools version ...