[CLSA-2026:1787239522] alt-python36-pip: Fix of 5 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-20 15:25:38 UTC
Description:
- CVE-2023-5752: option injection via Mercurial revision passed as a bare argument - CVE-2025-8869: arbitrary file write via unchecked symlink targets in tar extraction - CVE-2026-1703: path traversal via sibling-prefix directory containment check - CVE-2026-3219: archive format confusion for files matching both zip and tar signatures - CVE-2026-8643: arbitrary file write via entry point name escaping the scripts directory
Updated packages:
  • alt-python36-pip-20.2.4-7.el7.noarch.rpm
    sha:1e6dc5d74c772a09499da5ca61f0dd1939f9d8b4565209cd1007c2018929d8a9
  • alt-python36-pip-wheel-20.2.4-7.el7.noarch.rpm
    sha:99d2a2ebb32ef8b74c4109f10e255d7f89caaf539f04ee938be760100172f6e7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.