python3.11-setuptools-65.5.1-3.el8_10

エラータID: AXSA:2024-8681:02

Release date: 
Tuesday, August 20, 2024 - 11:26
Subject: 
python3.11-setuptools-65.5.1-3.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Setuptools is a collection of enhancements to the Python 3 distutils that allow you to more easily build and distribute Python 3 packages, especially ones that have dependencies on other packages. This package also contains the runtime components of setuptools, necessary to execute the software that requires pkg_resources.

Security Fix(es):

* pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools (CVE-2024-6345)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-6345
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python3.11-setuptools-65.5.1-3.el8_10.src.rpm
    MD5: cb34b6b7b6033d034641d70bfd959b05
    SHA-256: c5a3b6d4924beee1e1d68bc823e0a5352bb7de9b9a31d4c0d6b0bc76f879a636
    Size: 2.51 MB

Asianux Server 8 for x86_64
  1. python3.11-setuptools-65.5.1-3.el8_10.noarch.rpm
    MD5: a858f180cf84a553a6db9876935cd203
    SHA-256: bd190d7ff57cc9a8185872f1aa951a981ebfc5bc5a4fde04d91f170e3770b371
    Size: 1.96 MB
  2. python3.11-setuptools-wheel-65.5.1-3.el8_10.noarch.rpm
    MD5: 18e4fc1e9682d257f8f15e78e91c7918
    SHA-256: f4dc4d7d254ddbc2fe5ed124c9d85ace9b9735e2dc4ffdf4c2eae8bf512c7f3c
    Size: 720.51 kB