[CLSA-2026:1784372957] alt-python38-setuptools: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-21 17:36:25 UTC
Description:
- CVE-2022-40897: regex denial of service via crafted HTML in package_index - CVE-2024-6345: remote code execution via command injection in VCS download functions - CVE-2025-47273: path traversal in PackageIndex download filename resolution
Updated packages:
  • alt-python38-setuptools-58.3.0-3.el9.noarch.rpm
    sha:2c89971904e8413b871779ec35ddc9c9491c01a77d0c9ee7207b95be5cbd62bd
  • alt-python38-setuptools-wheel-58.3.0-3.el9.noarch.rpm
    sha:21b2f5563c11a152b7750cff7ce649b77af839010f67459a924b9c8dd3103f1d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.