[CLSA-2025:1759510077] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:48:04 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:fb2dda844367f781710a5f8d651c559738ba8a24
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:5102e1313e677488d73e4e47f5224e370db02685
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:9c7269b07ab58bb098c639a51bb71267c6938973
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:37c58ae46906bc9a68416ac44af20d25fc95d8e7
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:259ddc32f8ff8c58b4c08a46ba46148d79b9a577
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:9299649ac705b972743eb355044f129eefd438ba
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:5c333c32c1149aee13ca1c90ea66143d0f47ad0e
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:2b1388b97bc0580efa25c709af0a55f85211a339
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.