Release date:
2026-09-01 19:05:24 UTC
Description:
* SECURITY UPDATE: command injection in PackageIndex VCS downloads
- debian/patches/CVE-2024-6345.patch: pass argv lists to
subprocess.check_call() instead of interpolating the URL and revision
into an os.system() shell string (CWE-78).
- CVE-2024-6345
* SECURITY UPDATE: path traversal in the download filename
- debian/patches/CVE-2025-47273.patch: sanitise the name derived from the
URL so a percent-encoded absolute path cannot escape tmpdir (CWE-22).
- CVE-2025-47273
Updated packages:
-
alt-python312-setuptools_69.0.2-3_all.deb
sha:686df77e526f4bd1bcdeb39e5700034f5cd01835
-
alt-python312-setuptools-wheel_69.0.2-3_all.deb
sha:d7cc60595e292b6fe0ff45d9cd8bc13d446e0eb2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.