Lucene search

K
almalinuxAlmaLinuxALSA-2023:7176
HistoryNov 14, 2023 - 12:00 a.m.

Moderate: python-pip security update

2023-11-1400:00:00
errata.almalinux.org
18
python
pip
security update
tarfile
directory traversal
cve-2007-4559
package management
pypi
cvss score
almalinux release notes

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.027 Low

EPSS

Percentile

90.5%

pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package Index (PyPI). pip is a recursive acronym that can stand for either “Pip Installs Packages” or “Pip Installs Python”.

Security Fix(es):

  • python: tarfile module directory traversal (CVE-2007-4559)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.027 Low

EPSS

Percentile

90.5%