[CLSA-2025:1759509839] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:44:10 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:4336ea90d700e0752935abde16fa61ad4e5199b0
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:f3cc3e46bbe6a86f1b6e4b35e94204b57f5b1f17
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:7f0d00b2cc0304d4d3d30c033d4c129d3ba68667
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:86d0771d3f081c6f77f954f9262488314fa40184
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:a35fd657d7b8a566d7378320e5b2acf8e80dae28
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:38e3b6c9defdc3c9ed64edb13aaf440ada48f857
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:0fea1c2dade5f0d955817f1be239944d0c6e457d
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:0f66640d14f3763701e539ebaab29986d908e953
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.