[CLSA-2025:1759509928] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:45:36 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:676f5890335aa2da4a60c154e5b275ddc2534524
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:14bdf4316e594a900f9ba764b5880619cf98f9b2
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:05d265b9fab2b78477a26c26b7ba512cda156eb2
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:c0d7084c9f2bbd8c490d644d438bc4b38913f1f8
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:8ca8db50d9e225f95b3a9ef76bd041db26a77da9
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:0de24ae9317f48fe773070401d25e8103e1d9e00
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:1a77e498b1e891cc9b85d7df5109fb676d05dc77
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:d86fe7987b65ceb8c73f3612cb42e7374c37d380
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.