[CLSA-2026:1788277502] alt-python27-pip: Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-09-01 15:45:17 UTC
Description:
- CVE-2023-5752: option injection via Mercurial revision passed as a bare argument - CVE-2025-8869: arbitrary file write via unchecked symlink targets in tar extraction - CVE-2026-1703: path traversal via sibling-prefix directory containment check - CVE-2026-3219: archive format confusion for files matching both zip and tar signatures - CVE-2026-8643: arbitrary file write via entry point name escaping the scripts directory - CVE-2026-13346: directory escape via Link.filename decoding the URL path twice - CVE-2021-3572: revision hijacking via unicode separators in git references
Updated packages:
  • alt-python27-pip-20.2.4-6.el10.noarch.rpm
    sha:283ffd0e60b82adc7d2b39a730757066074195eb4f7bc1f1a4f0540d4d3ae4f8
  • alt-python27-pip-wheel-20.2.4-6.el10.noarch.rpm
    sha:e9301218cc390e5c6f820f7e970b49cef260859280f8c46e46d6c786b8670f2e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.