Bug 34390 - python-setuptools new security issue CVE-2025-47273
Summary: python-setuptools new security issue CVE-2025-47273
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-06-23 16:49 CEST by Nicolas Salguero
Modified: 2025-11-14 00:38 CET (History)
2 users (show)

See Also:
Source RPM: python-setuptools-65.5.0-3.1.mga9.src.rpm
CVE: CVE-2025-47273
Status comment:


Attachments

Nicolas Salguero 2025-06-23 16:50:36 CEST

Status comment: (none) => Patch available from Fedora and upstream
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => python-setuptools-65.5.0-3.1.mga9.src.rpm
CVE: (none) => CVE-2025-47273

Comment 1 Lewis Smith 2025-06-24 22:01:25 CEST
Fix URL given; over to Python.

Assignee: bugsquad => python

Comment 2 Nicolas Salguero 2025-11-10 09:40:27 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write. (CVE-2025-47273)

References:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QJ375SF7FQYZCXBVGMYYQXBL5RK5ORGD/
========================

Updated packages in core/updates_testing:
========================
python-setuptools-wheel-65.5.0-3.2.mga9
python3-setuptools-65.5.0-3.2.mga9

from SRPM:
python-setuptools-65.5.0-3.2.mga9.src.rpm

Status: NEW => ASSIGNED
Status comment: Patch available from Fedora and upstream => (none)
Assignee: python => qa-bugs
Whiteboard: MGA9TOO => (none)

Comment 3 Thomas Andrews 2025-11-10 22:58:10 CET
MGA9-64 Plasma.

To satisfy dependencies, the following packages are going to be installed:
  Package                        Version      Release       Arch    
(medium "QA Testing (64-bit)")
  python-setuptools-wheel        65.5.0       3.2.mga9      noarch  
  python3-setuptools             65.5.0       3.2.mga9      noarch  
269B of additional disk space will be used.
1.9MB of packages will be retrieved.
Proceed with the installation of the 2 packages? (Y/n) 


installing python3-setuptools-65.5.0-3.2.mga9.noarch.rpm python-setuptools-wheel-65.5.0-3.2.mga9.noarch.rpm from //home/tom/qa-testing/x86_64
Preparing...                     ######################################################################################################################################################
      1/2: python-setuptools-wheel
                                 ######################################################################################################################################################
      2/2: python3-setuptools    ######################################################################################################################################################
      1/2: removing python-setuptools-wheel-65.5.0-3.1.mga9.noarch
                                 ######################################################################################################################################################
      2/2: removing python3-setuptools-65.5.0-3.1.mga9.noarch
                                 ######################################################################################################################################################

A clean update was sufficient for bug 31421, so it's good enough here.

Validating.

Whiteboard: (none) => MGA9-64-OK
Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2025-11-13 20:23:03 CET

Keywords: (none) => advisory

Comment 4 Mageia Robot 2025-11-14 00:38:14 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0288.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.