Bug 31421 - python-setuptools new security issue CVE-2022-40897
Summary: python-setuptools new security issue CVE-2022-40897
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 8
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA8-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2023-01-17 22:58 CET by David Walser
Modified: 2023-07-07 07:56 CEST (History)
5 users (show)

See Also:
Source RPM: python-setuptools-65.5.0-1.mga9.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2023-01-17 22:58:10 CET
openSUSE has issued an advisory on January 16:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/WAQKKYI5XTBXPHU7RRPHNAQ7W6ARWJQW/

Mageia 8 is also affected.
David Walser 2023-01-17 22:58:28 CET

Status comment: (none) => Patch available from openSUSE
Whiteboard: (none) => MGA8TOO

Comment 1 David Walser 2023-01-23 21:51:16 CET
Ubuntu has issued an advisory for this today (January 23):
https://ubuntu.com/security/notices/USN-5817-1

The issue is fixed upstream in 65.5.1.

Severity: normal => major

Comment 2 David Walser 2023-02-23 18:02:13 CET
RedHat has issued an advisory for this on February 21:
https://access.redhat.com/errata/RHSA-2023:0835
Comment 3 David Walser 2023-05-07 01:41:43 CEST
Fedora has issued an advisory for this on April 30:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H/
Comment 4 David GEIGER 2023-06-30 06:16:06 CEST
patch added for both mga8 and cauldron!


Packages in 9/Core/Updates_testing:
======================
python-setuptools-wheel-65.5.0-3.mga9.noarch.rpm
python3-setuptools-65.5.0-3.mga9.noarch.rpm

Packages in 8/Core/Updates_testing:
======================
python-setuptools-wheel-56.2.0-1.1.mga8.noarch.rpm
python3-setuptools-56.2.0-1.1.mga8.noarch.rpm
python3-pkg-resources-56.2.0-1.1.mga8.noarch.rpm


From SRPMS:
python-setuptools-65.5.0-3.mga9.src.rpm
python-setuptools-56.2.0-1.1.mga8.src.rpm

CC: (none) => geiger.david68210
Assignee: python => qa-bugs

David Walser 2023-06-30 15:45:37 CEST

Status comment: Patch available from openSUSE => (none)

Comment 5 David GEIGER 2023-06-30 16:48:30 CEST
Packages moved for cauldron!

Version: Cauldron => 8
Whiteboard: MGA8TOO => (none)

Comment 6 Len Lawrence 2023-07-01 18:14:55 CEST
Mageia8, x86_64

All three packages were already available and updated cleanly.
There are 67 packages in the requires-recursive list but this is developer country so we should simply move it on.

CC: (none) => tarazed25
Whiteboard: (none) => MGA8-64-OK

Comment 7 Thomas Andrews 2023-07-01 22:24:39 CEST
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Dave Hodgins 2023-07-06 22:39:53 CEST

Keywords: (none) => advisory
CC: (none) => davidwhodgins

Comment 8 Mageia Robot 2023-07-07 07:56:27 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2023-0219.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.