UbuntuUpdates.org

Package "python-wheel-common"

Name: python-wheel-common

Description:

built-package format for Python (command-line scripts)

Latest version: 0.34.2-1ubuntu0.1
Release: focal (20.04)
Level: security
Repository: universe
Head package: wheel
Homepage: https://github.com/pypa/wheel

Links


Download "python-wheel-common"


Other versions of "python-wheel-common" in Focal

Repository Area Version
base universe 0.34.2-1
updates universe 0.34.2-1ubuntu0.1

Changelog

Version: 0.34.2-1ubuntu0.1 2023-01-24 10:07:20 UTC

  wheel (0.34.2-1ubuntu0.1) focal-security; urgency=medium

  * SECURITY UPDATE: ReDOS in wheelfile.py
    - debian/patches/CVE-2022-40898.patch: Fix potential DoS attack
      via WHEEL_INFO_RE by restricting matching dash and dot characters
      in src/wheel/wheelfile.py.
    - CVE-2022-40898

 -- David Fernandez Gonzalez <email address hidden> Mon, 23 Jan 2023 11:31:23 +0100

CVE-2022-40898 An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker c



About   -   Send Feedback to @ubuntu_updates