|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: python3-pip,python310-pip,python311-pip: unnecessary windows exe files shipped | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Marcus Meissner <meissner> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | andreas.taschner, brad.bendily, bugzilla-notif-sf, gianluca.gabrielli, meissner, mmachova, nicola.dimarzo, rfrohl, roberto.angelino |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | Other | ||
| OS: | Other | ||
| URL: | https://smash.suse.de/issue/368392/ | ||
| Whiteboard: | |||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
|
Description
Marcus Meissner
2023-06-05 09:55:38 UTC
they are also in the pip wheel in the python3xx packages. full list of exe files: ./SUSE:SLE-12-SP1:Update/python/Python-2.7.18/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-12-SP1:Update/python/Python-2.7.18/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-12-SP1:Update/python/Python-2.7.18/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-12-SP1:Update/python/Python-2.7.18/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-12-SP1:Update/python/Python-2.7.18/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-10.0.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-14.0-amd64.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-14.0.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-10.0-amd64.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-11-SP1:Update:Teradata/python27/Python-2.7.18/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-11-SP1:Update:Teradata/python27/Python-2.7.18/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-11-SP1:Update:Teradata/python27/Python-2.7.18/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-11-SP1:Update:Teradata/python27/Python-2.7.18/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-11-SP1:Update:Teradata/python27/Python-2.7.18/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-12-SP4:Update/python/Python-2.7.18/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-12-SP4:Update/python/Python-2.7.18/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-12-SP4:Update/python/Python-2.7.18/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-12-SP4:Update/python/Python-2.7.18/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-12-SP4:Update/python/Python-2.7.18/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-14.0.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-10.0.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-14.0-amd64.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-10.0-amd64.exe ./SUSE:SLE-15-SP3:Update/python39/Python-3.9.16/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-15:Update/python/Python-2.7.18/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-15:Update/python/Python-2.7.18/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-15:Update/python/Python-2.7.18/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-15:Update/python/Python-2.7.18/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-15:Update/python/Python-2.7.18/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-10.0.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-14.0-amd64.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-14.0.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-10.0-amd64.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-12-SP5:Update/python36/Python-3.6.15/Lib/distutils/command/wininst-9.0-amd64.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-14.0.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-6.0.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-10.0.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-9.0-amd64.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-9.0.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-14.0-amd64.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-8.0.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-10.0-amd64.exe ./openSUSE:Factory/python39/Python-3.9.16/Lib/distutils/command/wininst-7.1.exe ./openSUSE:Factory/python/Python-2.7.18/Lib/distutils/command/wininst-7.1.exe ./openSUSE:Factory/python/Python-2.7.18/Lib/distutils/command/wininst-9.0.exe ./openSUSE:Factory/python/Python-2.7.18/Lib/distutils/command/wininst-8.0.exe ./openSUSE:Factory/python/Python-2.7.18/Lib/distutils/command/wininst-6.0.exe ./openSUSE:Factory/python/Python-2.7.18/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-12:Update/python3/Python-3.4.10/Lib/distutils/command/wininst-9.0-amd64.exe ./SUSE:SLE-12:Update/python3/Python-3.4.10/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-12:Update/python3/Python-3.4.10/Lib/distutils/command/wininst-10.0-amd64.exe ./SUSE:SLE-12:Update/python3/Python-3.4.10/Lib/distutils/command/wininst-10.0.exe ./SUSE:SLE-12:Update/python3/Python-3.4.10/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-12:Update/python3/Python-3.4.10/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-12:Update/python3/Python-3.4.10/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-11-SP1:Update/python/Python-2.6.9/Lib/distutils/command/wininst-6.0.exe ./SUSE:SLE-11-SP1:Update/python/Python-2.6.9/Lib/distutils/command/wininst-9.0.exe ./SUSE:SLE-11-SP1:Update/python/Python-2.6.9/Lib/distutils/command/wininst-7.1.exe ./SUSE:SLE-11-SP1:Update/python/Python-2.6.9/Lib/distutils/command/wininst-8.0.exe ./SUSE:SLE-11-SP1:Update/python/Python-2.6.9/Lib/distutils/command/wininst-9.0-amd64.exe This is an autogenerated message for OBS integration: This bug (1212015) was mentioned in https://build.opensuse.org/request/show/1092512 Factory / python-pip Hi, I am confused. This bug report is about pip, but the mentioned list of .exe files comes from the Python standard library and it doesn't mention pip. Second, did Daniel's request fix the issue in the Factory for you and should I reproduce it in SLE? It did for me (there are no .exe files in `rpm -ql python310-pip-23.1.2-2.2.noarch.rpm`), but I am not sure whether we are talking about the same issue. In the end I inspired myself at https://smelt.suse.de/maintained/ and applied the change from https://build.opensuse.org/request/show/1092512 accordingly. Sending bunch of requests and reassigning to security. SUSE-SU-2023:3184-1: An update that has one fix can now be installed. Category: security (low) Bug References: 1212015 Sources used: SUSE Linux Enterprise Real Time 15 SP3 (src): python-pip-wheel-10.0.1-150000.3.12.1 SUSE Manager Proxy 4.2 (src): python-pip-wheel-10.0.1-150000.3.12.1 SUSE Manager Retail Branch Server 4.2 (src): python-pip-wheel-10.0.1-150000.3.12.1 SUSE Manager Server 4.2 (src): python-pip-wheel-10.0.1-150000.3.12.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2023:3183-1: An update that has one fix can now be installed. Category: security (low) Bug References: 1212015 Sources used: SUSE Manager Retail Branch Server 4.2 (src): python-pip-20.0.2-150100.6.21.1 SUSE Manager Server 4.2 (src): python-pip-20.0.2-150100.6.21.1 SUSE Linux Enterprise Real Time 15 SP3 (src): python-pip-20.0.2-150100.6.21.1 SUSE Manager Proxy 4.2 (src): python-pip-20.0.2-150100.6.21.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2023:2932-1: An update that has one security fix can now be installed. Category: security (low) Bug References: 1212015 Sources used: Python 3 Module 15-SP5 (src): python-pip-22.3.1-150400.17.6.1 openSUSE Leap 15.4 (src): python-pip-22.3.1-150400.17.6.1 openSUSE Leap 15.5 (src): python-pip-22.3.1-150400.17.6.1 Python 3 Module 15-SP4 (src): python-pip-22.3.1-150400.17.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2023:2933-1: An update that has one security fix can now be installed. Category: security (low) Bug References: 1212015 Sources used: SUSE Linux Enterprise High Performance Computing 12 SP5 (src): python-pip-10.0.1-13.11.1 SUSE Linux Enterprise Server 12 SP5 (src): python-pip-10.0.1-13.11.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): python-pip-10.0.1-13.11.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2024:0784-1: An update that solves four vulnerabilities, contains two features and has two security fixes can now be installed. Category: security (important) Bug References: 1196025, 1210638, 1212015, 1214692, 1215454, 1219666 CVE References: CVE-2022-25236, CVE-2023-27043, CVE-2023-40217, CVE-2023-6597 Jira References: PED-7886, SLE-21253 Sources used: openSUSE Leap 15.3 (src): python39-3.9.18-150300.4.38.1, python39-core-3.9.18-150300.4.38.1, python39-documentation-3.9.18-150300.4.38.1 openSUSE Leap 15.5 (src): python39-3.9.18-150300.4.38.1, python39-core-3.9.18-150300.4.38.1, python39-documentation-3.9.18-150300.4.38.1 SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (src): python39-3.9.18-150300.4.38.1, python39-core-3.9.18-150300.4.38.1 SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (src): python39-3.9.18-150300.4.38.1, python39-core-3.9.18-150300.4.38.1 SUSE Linux Enterprise Server for SAP Applications 15 SP3 (src): python39-3.9.18-150300.4.38.1, python39-core-3.9.18-150300.4.38.1 SUSE Enterprise Storage 7.1 (src): python39-3.9.18-150300.4.38.1, python39-core-3.9.18-150300.4.38.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. done, closing |