python3-setuptools-39.2.0-10.0.5.0.1.el7.AXS7
エラータID: AXSA:2025-11012:02
Setuptools is a collection of enhancements to the Python 3 distutils that allow
you to more easily build and distribute Python 3 packages, especially ones that
have dependencies on other packages.
This package also contains the runtime components of setuptools, necessary to
execute the software that requires pkg_resources.py.
Security Fix(es):
* CVE-2022-40897: fix Regular Expression Denial of Service (ReDoS) in
package_index.py
* CVE-2024-6345: fix remote code execution in package_index module
CVE(s):
CVE-2022-40897
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
CVE-2024-6345
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.
Update packages.
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these functions are exposed to user-controlled inputs, such as package URLs, they can execute arbitrary commands on the system. The issue is fixed in version 70.0.
N/A
Asianux Server 7 for x86_64
- python3-setuptools-39.2.0-10.0.5.0.1.el7.AXS7.noarch.rpm
MD5: eeae69baa76ec477098615e542c7022b
SHA-256: 3ad4e53ded2c6d8ddd5f68e887dcbb165de7b8b0ba9819a691128ea4f07f1b4b
Size: 628.97 kB