Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20993-1

Опубликовано: 20 июн. 2026
Источник: suse-cvrf

Описание

Security update for python-pip

This update for python-pip fixes the following issue

  • CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669).

Список пакетов

openSUSE Leap 16.0
python313-pip-25.0.1-160000.5.1
python313-pip-wheel-25.0.1-160000.5.1

Описание

pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.


Затронутые продукты
openSUSE Leap 16.0:python313-pip-25.0.1-160000.5.1
openSUSE Leap 16.0:python313-pip-wheel-25.0.1-160000.5.1

Ссылки