[CLSA-2025:1759510256] Fix CVE(s): CVE-2019-20907, CVE-2019-9674
Type:
security
Severity:
Important
Release date:
2025-10-03 16:51:00 UTC
Description:
* SECURITY UPDATE: zip bomb vulnerability in Lib/zipfile.py - debian/patches/CVE-2019-9674.patch: add pitfalls to zipfile module documentation - CVE-2019-9674 * SECURITY UPDATE: Infinite loop - debian/patches/CVE-2019-20907.patch: avoid infinite loop in the tarfile module in Lib/tarfile.py, Lib/test/test_tarfile.py. - CVE-2019-20907
Updated packages:
  • alt-python27_2.7.18-3_amd64.deb
    sha:3b745fb6f1088e959fd26a84f6292e4efdf7738b
  • alt-python27-debug_2.7.18-3_amd64.deb
    sha:090c0cd3337ca48722a231e8eed0ece22d0c3859
  • alt-python27-devel_2.7.18-3_amd64.deb
    sha:e045f735d4ba09db2149f7f8d233f6937507cd6c
  • alt-python27-idle_2.7.18-3_amd64.deb
    sha:0a2bec4a729427220c80ce16ffacb2a101dac24a
  • alt-python27-libs_2.7.18-3_amd64.deb
    sha:8f9a6d279cef4b8dda1563932dc5bcf6977220dc
  • alt-python27-test_2.7.18-3_amd64.deb
    sha:0fed05815130fb273f6f90c8ce86cedc866884b3
  • alt-python27-tkinter_2.7.18-3_amd64.deb
    sha:ededea6ea6b1ef4259640307bc773150f6301a81
  • alt-python27-tools_2.7.18-3_amd64.deb
    sha:5c431148b2ee58f061bbf3118f868edc640cb191
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.