New Debian setuptools 66.1.1-1+deb12u1 fixes: This update addresses the following issue: * pypa/setuptools: Remote code execution via download functions in the package_index module in pypa/setuptools (CVE-2024-6345)
--- mirror/ftp/pool/main/s/setuptools/setuptools_66.1.1-1.dsc +++ apt/ucs_5.2-0-errata5.2-0/source/setuptools_66.1.1-1+deb12u1.dsc @@ -1,3 +1,11 @@ +66.1.1-1+deb12u1 [Tue, 31 Dec 2024 01:08:15 +0100] Daniel Leidert <dleidert@debian.org>: + + * Non-maintainer upload by the Debian LTS team. + * debian/patches/CVE-2024-6345.patch: Fix CVE-2024-6345. + - Replace the unsafe use of os.system to fix a possible remote code + execution by supplying malicious URLs in a package index or via the + command line. + 66.1.1-1 [Fri, 27 Jan 2023 07:49:44 +0100] Matthias Klose <doko@debian.org>: * New upstream version. <http://piuparts.knut.univention.de/5.2-0/#6855102236809079973>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-0] ff266ad6ee Bug #57917: setuptools 66.1.1-1+deb12u1 doc/errata/staging/setuptools.yaml | 13 +++++++++++++ 1 file changed, 13 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x19>