Количество 61
Количество 61
ELSA-2025-14900
ELSA-2025-14900: python39:3.9 security update (MODERATE)

CVE-2025-8194
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVE-2025-8194
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1

CVE-2025-8194
There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1
CVE-2025-8194
There is a defect in the CPython \u201ctarfile\u201d module affecting ...

CVE-2025-47273
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVE-2025-47273
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVE-2025-47273
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

CVE-2025-47273
CVE-2025-47273
setuptools is a package that allows users to download, build, install, ...

SUSE-SU-2025:03032-1
Security update for python

SUSE-SU-2025:02984-1
Security update for python311

SUSE-SU-2025:02983-1
Security update for python36

SUSE-SU-2025:02982-1
Security update for python312

SUSE-SU-2025:02948-1
Security update for python310

SUSE-SU-2025:02701-1
Security update for python

SUSE-SU-2025:02700-1
Security update for python39

RLSA-2025:14984
Moderate: python3.12 security update

RLSA-2025:14841
Moderate: python3.11 security update

RLSA-2025:14546
Moderate: python3.12 security update
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
ELSA-2025-14900 ELSA-2025-14900: python39:3.9 security update (MODERATE) | около 2 месяцев назад | |||
![]() | CVE-2025-8194 There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1 | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
![]() | CVE-2025-8194 There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1 | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
![]() | CVE-2025-8194 There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously crafted tar archives. This vulnerability can be mitigated by including the following patch after importing the “tarfile” module: https://gist.github.com/sethmlarson/1716ac5b82b73dbcbf23ad2eff8b33e1 | CVSS3: 7.5 | 0% Низкий | 3 месяца назад |
CVE-2025-8194 There is a defect in the CPython \u201ctarfile\u201d module affecting ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
![]() | CVE-2025-47273 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад |
![]() | CVE-2025-47273 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue. | CVSS3: 7.1 | 0% Низкий | 5 месяцев назад |
![]() | CVE-2025-47273 setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue. | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад |
![]() | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
CVE-2025-47273 setuptools is a package that allows users to download, build, install, ... | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
![]() | SUSE-SU-2025:03032-1 Security update for python | 0% Низкий | около 2 месяцев назад | |
![]() | SUSE-SU-2025:02984-1 Security update for python311 | 0% Низкий | около 2 месяцев назад | |
![]() | SUSE-SU-2025:02983-1 Security update for python36 | 0% Низкий | около 2 месяцев назад | |
![]() | SUSE-SU-2025:02982-1 Security update for python312 | 0% Низкий | около 2 месяцев назад | |
![]() | SUSE-SU-2025:02948-1 Security update for python310 | 0% Низкий | около 2 месяцев назад | |
![]() | SUSE-SU-2025:02701-1 Security update for python | 0% Низкий | 2 месяца назад | |
![]() | SUSE-SU-2025:02700-1 Security update for python39 | 0% Низкий | 2 месяца назад | |
![]() | RLSA-2025:14984 Moderate: python3.12 security update | 0% Низкий | 13 дней назад | |
![]() | RLSA-2025:14841 Moderate: python3.11 security update | 0% Низкий | около 1 месяца назад | |
![]() | RLSA-2025:14546 Moderate: python3.12 security update | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу