openSUSE has issued an advisory on August 28: https://lists.suse.com/pipermail/sle-updates/2024-August/036709.html
Whiteboard: (none) => MGA9TOOSource RPM: (none) => python-setuptools-69.0.2-3.mga10.src.rpm, python-setuptools-65.5.0-3.mga9.src.rpmStatus comment: (none) => Fixed upstream in 70.0.0 and patch available from upstream and openSUSECVE: (none) => CVE-2024-6345
Assigning to Python. Will look into the patch.
Assignee: bugsquad => pythonlulu
Assignee: pythonlulu => python
CC: (none) => marja11URL: (none) => https://lists.suse.com/pipermail/sle-updates/2024-August/036709.html
From: https://bugzilla.suse.com/show_bug.cgi?id=1228105 This is a patch, but for this issue?: https://github.com/pypa/setuptools/commit/88807c7062788254f654ea8c03427adc859321f0
Already fixed in Cauldron.
Whiteboard: MGA9TOO => (none)Version: Cauldron => 9Source RPM: python-setuptools-69.0.2-3.mga10.src.rpm, python-setuptools-65.5.0-3.mga9.src.rpm => python-setuptools-65.5.0-3.mga9.src.rpm
Suggested advisory: ======================== The updated packages fix a security vulnerability: Remote Code Execution in pypa/setuptools. (CVE-2024-6345) References: https://lists.suse.com/pipermail/sle-updates/2024-August/036709.html ======================== Updated packages in core/updates_testing: ======================== python-setuptools-wheel-65.5.0-3.1.mga9 python3-setuptools-65.5.0-3.1.mga9 from SRPM: python-setuptools-65.5.0-3.1.mga9.src.rpm
Status: NEW => ASSIGNEDAssignee: python => qa-bugsStatus comment: Fixed upstream in 70.0.0 and patch available from upstream and openSUSE => (none)
Keywords: (none) => advisory
RH x86_64 installing python-setuptools-wheel-65.5.0-3.1.mga9.noarch.rpm python3-setuptools-65.5.0-3.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/2: python3-setuptools ################################################################################################## 2/2: python-setuptools-wheel ################################################################################################## 1/2: removing python3-setuptools-65.5.0-3.mga9.noarch ################################################################################################## 2/2: removing python-setuptools-wheel-65.5.0-3.mga9.noarch ################################################################################################## Look like clean install is the OK criteria
CC: (none) => andrewsfarmWhiteboard: (none) => MGA9-64-OK
Validating.
CC: (none) => sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0056.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED