Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2899-1

Опубликовано: 14 авг. 2024
Источник: suse-cvrf

Описание

Security update for python-setuptools

This update for python-setuptools fixes the following issues:

  • CVE-2024-6345: Fixed code execution via download functions in the package_index module (bsc#1228105)

Список пакетов

Image SLES15-SP3-BYOS-Azure
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-BYOS-EC2-HVM
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-BYOS-GCE
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-CHOST-BYOS-Aliyun
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-CHOST-BYOS-Azure
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-CHOST-BYOS-EC2
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-CHOST-BYOS-GCE
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-HPC-BYOS-Azure
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-HPC-BYOS-EC2-HVM
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-HPC-BYOS-GCE
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-Micro-5-1-BYOS-Azure
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-Micro-5-1-BYOS-EC2-HVM
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-Micro-5-1-BYOS-GCE
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-Micro-5-2-BYOS-Azure
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-Micro-5-2-BYOS-EC2-HVM
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-Micro-5-2-BYOS-GCE
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAP-BYOS-Azure
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAP-BYOS-GCE
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAPCAL-Azure
python2-setuptools-40.5.0-150100.6.9.1
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAPCAL-EC2-HVM
python2-setuptools-40.5.0-150100.6.9.1
python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-SAPCAL-GCE
python2-setuptools-40.5.0-150100.6.9.1
python3-setuptools-40.5.0-150100.6.9.1
SUSE Enterprise Storage 7.1
python3-setuptools-40.5.0-150100.6.9.1
python3-setuptools-test-40.5.0-150100.6.9.1
python3-setuptools-wheel-40.5.0-150100.6.9.1
SUSE Linux Enterprise High Performance Computing 15 SP2-LTSS
python2-setuptools-40.5.0-150100.6.9.1
python3-setuptools-40.5.0-150100.6.9.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
python3-setuptools-40.5.0-150100.6.9.1
python3-setuptools-test-40.5.0-150100.6.9.1
python3-setuptools-wheel-40.5.0-150100.6.9.1
SUSE Linux Enterprise Micro 5.1
python3-setuptools-40.5.0-150100.6.9.1
SUSE Linux Enterprise Micro 5.2
python3-setuptools-40.5.0-150100.6.9.1
SUSE Linux Enterprise Server 15 SP2-LTSS
python2-setuptools-40.5.0-150100.6.9.1
python3-setuptools-40.5.0-150100.6.9.1
SUSE Linux Enterprise Server 15 SP3-LTSS
python3-setuptools-40.5.0-150100.6.9.1
python3-setuptools-test-40.5.0-150100.6.9.1
python3-setuptools-wheel-40.5.0-150100.6.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP2
python2-setuptools-40.5.0-150100.6.9.1
python3-setuptools-40.5.0-150100.6.9.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
python3-setuptools-40.5.0-150100.6.9.1
python3-setuptools-test-40.5.0-150100.6.9.1
python3-setuptools-wheel-40.5.0-150100.6.9.1

Описание

A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.


Затронутые продукты
Image SLES15-SP3-BYOS-Azure:python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-BYOS-EC2-HVM:python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-BYOS-GCE:python3-setuptools-40.5.0-150100.6.9.1
Image SLES15-SP3-CHOST-BYOS-Aliyun:python3-setuptools-40.5.0-150100.6.9.1

Ссылки
Уязвимость SUSE-SU-2024:2899-1