Release date:
2026-07-21 17:46:30 UTC
Description:
- CVE-2022-40897: regex denial of service via crafted HTML in package_index
- CVE-2024-6345: remote code execution via command injection in VCS download functions
- CVE-2025-47273: path traversal in PackageIndex download filename resolution
Updated packages:
-
alt-python38-setuptools-58.3.0-3.el8.noarch.rpm
sha:e6f981c1d796ce2f75bb1e6445bb764431b70ceeefea7b0a596eabc9d2ed1203
-
alt-python38-setuptools-wheel-58.3.0-3.el8.noarch.rpm
sha:32c782b65321267982ad0a1a59326e3b7e62004362c013e7e26f3dfe3d0255f7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.