Lucene search

K
redhatRedHatRHSA-2023:6914
HistoryNov 14, 2023 - 8:40 a.m.

(RHSA-2023:6914) Moderate: python3.11-pip security update

2023-11-1408:40:05
access.redhat.com
24
security update
python3.11-pip
package management system
python
pypi
cve-2007-4559
red hat enterprise linux 8.9.

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

High

EPSS

0.093

Percentile

94.8%

pip is a package management system used to install and manage software packages written in Python. Many packages can be found in the Python Package Index (PyPI). pip is a recursive acronym that can stand for either “Pip Installs Packages” or “Pip Installs Python”.

Security Fix(es):

  • python: tarfile module directory traversal (CVE-2007-4559)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.9 Release Notes linked from the References section.

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

High

EPSS

0.093

Percentile

94.8%