[CLSA-2025:1765801059] python-setuptools: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2025-12-15 12:17:43 UTC
Description:
- CVE-2024-6345: fix code injection vulnerability in package download functions - CVE-2025-47273: fix path traversal in PackageIndex.download leading to arbitrary file write
Updated packages:
  • python3-setuptools-53.0.0-12.el9.tuxcare.els1.noarch.rpm
    sha:3edde557c692f13e39e2c541858a3b98616fdd0b8e5f4725e251a570057d323e
  • python3-setuptools-wheel-53.0.0-12.el9.tuxcare.els1.noarch.rpm
    sha:78e6fc1c91aef7203319438a5ae0d929144155d8af4cbe35533b44ff27831901
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.