[CLSA-2025:1759510002] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:46:47 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:618933e6f2f456e5d7576c703ab34460615b4bca
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:c643adbb1f9428e598414644e76acbe2b7080df1
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:49d88ca16dd6fb8a252abcdd640c59b80f5f08e3
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:17b9465dc9f9cc57c9d50fe141578a3b6d9eb685
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:73c6d0548abcabdca19b668beb662ce2bbfde722
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:8ef98b385d2f4161e4a8a743089ce68c44bfbdde
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:7ca9402ccdc5bbe647e551806ce11274ac33b62c
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:79ee46587f6a9e910d2e386db35374a230f0e6c9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.