Bug 33395 - python-zipp new security issue CVE-2024-5569
Summary: python-zipp new security issue CVE-2024-5569
Status: NEW
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: Cauldron
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Python Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard: MGA9TOO
Keywords:
Depends on:
Blocks:
 
Reported: 2024-07-12 15:23 CEST by Nicolas Salguero
Modified: 2024-07-12 20:46 CEST (History)
0 users

See Also:
Source RPM: python-zipp-3.8.1-4.mga10.src.rpm, python-zipp-3.8.1-3.mga9.src.rpm
CVE: CVE-2024-5569
Status comment: Fixed upstream in 3.19.1 and patch available from upstream and openSUSE


Attachments

Description Nicolas Salguero 2024-07-12 15:23:32 CEST
SUSE has issued an advisory on July 11:
https://lists.suse.com/pipermail/sle-updates/2024-July/035932.html

The problem is fixed in versions 3.19.1 and above.
The fix is: https://github.com/jaraco/zipp/commit/fd604bd34f0343472521a36da1fbd22e793e14fd

Mageia 9 is also affected.
Nicolas Salguero 2024-07-12 15:24:58 CEST

CVE: (none) => CVE-2024-5569
Status comment: (none) => Fixed upstream in 3.19.1 and patch available from upstream and openSUSE
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => python-zipp-3.8.1-4.mga10.src.rpm, python-zipp-3.8.1-3.mga9.src.rpm

Comment 1 Lewis Smith 2024-07-12 20:46:48 CEST
Assigning to Python maintainers.

Assignee: bugsquad => python


Note You need to log in before you can comment on or make changes to this bug.