Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-FU-2021:2130-1

Опубликовано: 23 июн. 2021
Источник: suse-cvrf

Описание

Feature implementation for python39-pip, python39-setuptools

This update for python39-pip, python39-setuptools fixes the following issues:

Changes in python39-setuptools:

  • Provide python39-setuptools version 44.1.1 with vendored dependencies. (jsc#SLE-17532, jsc#SLE-17957)

Changes in python39-pip:

  • Provide python39-pip version 20.2.4 with vendored dependencies. (jsc#SLE-17532, jsc#SLE-17957)

Список пакетов

Container bci/python:3
python39-pip-20.2.4-7.5.1
python39-setuptools-44.1.1-7.3.1
Container containers/python:3.9
python39-pip-20.2.4-7.5.1
python39-setuptools-44.1.1-7.3.1
Image python_15_6
python39-pip-20.2.4-7.5.1
python39-setuptools-44.1.1-7.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP3
python39-pip-20.2.4-7.5.1
python39-setuptools-44.1.1-7.3.1

Описание

The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.


Затронутые продукты
Container bci/python:3:python39-pip-20.2.4-7.5.1
Container bci/python:3:python39-setuptools-44.1.1-7.3.1
Container containers/python:3.9:python39-pip-20.2.4-7.5.1
Container containers/python:3.9:python39-setuptools-44.1.1-7.3.1

Ссылки

Описание

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.


Затронутые продукты
Container bci/python:3:python39-pip-20.2.4-7.5.1
Container bci/python:3:python39-setuptools-44.1.1-7.3.1
Container containers/python:3.9:python39-pip-20.2.4-7.5.1
Container containers/python:3.9:python39-setuptools-44.1.1-7.3.1

Ссылки

Описание

The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.


Затронутые продукты
Container bci/python:3:python39-pip-20.2.4-7.5.1
Container bci/python:3:python39-setuptools-44.1.1-7.3.1
Container containers/python:3.9:python39-pip-20.2.4-7.5.1
Container containers/python:3.9:python39-setuptools-44.1.1-7.3.1

Ссылки

Описание

The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.


Затронутые продукты
Container bci/python:3:python39-pip-20.2.4-7.5.1
Container bci/python:3:python39-setuptools-44.1.1-7.3.1
Container containers/python:3.9:python39-pip-20.2.4-7.5.1
Container containers/python:3.9:python39-setuptools-44.1.1-7.3.1

Ссылки