[CLSA-2025:1759510186] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:49:50 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:4a5391e286b171326410518c8a9e170dd60a1820
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:621d20c1a568ed97041046f92c1db64f8330d3a5
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:b5dea74d5527a831772404a4d456c8487a48e515
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:414c6274c9e3c96bc68f9708aa0fad729f932916
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:dd98d21b00715597f2fc8082100f912c28b5c9fe
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:2870197a64a7540e37fd303c9bcc7b6c68dc5271
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:b2aca19216141861a5df039ee08a1e9232a4e91a
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:5c4e071a30ef3e1d4cc19e321b3effbf0edca6a7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.