python3.11-setuptools-65.5.1-4.el8_10

エラータID: AXSA:2025-10503:01

Release date: 
Thursday, July 17, 2025 - 13:18
Subject: 
python3.11-setuptools-65.5.1-4.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

* setuptools: Path Traversal Vulnerability in setuptools PackageIndex (CVE-2025-47273)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-47273
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of the process running the Python code, which could escalate to remote code execution depending on the context. Version 78.1.1 fixes the issue.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. python3.11-setuptools-65.5.1-4.el8_10.src.rpm
    MD5: 0e7843bdc1a7058379e267b63cbd4a27
    SHA-256: 5b4142fd1ddd74354b829a4929297430f1affd02bb08a1cc56995c0becc7ab47
    Size: 2.51 MB

Asianux Server 8 for x86_64
  1. python3.11-setuptools-65.5.1-4.el8_10.noarch.rpm
    MD5: d6e2a87fb30ad23919ca306480b8d696
    SHA-256: 838bfeb2b2d0a2972e945cbc11f0e79e20f12a0b0b10ef29b72ae57acb35ef69
    Size: 1.96 MB
  2. python3.11-setuptools-wheel-65.5.1-4.el8_10.noarch.rpm
    MD5: f7041206a09684266f1041bfad08a355
    SHA-256: 52bffba16ba30eadb9f9238919c725a3fdd7fa4440b57737273178e9cbbb3ed1
    Size: 720.67 kB