ALT-BU-2025-7422-1
Branch p10 update bulletin.
Package python3-module-virtualenv updated to version 20.30.0-alt0.p10.1 for branch p10 in task 380082.
Closed vulnerabilities
Modified: 2025-08-13
BDU:2024-10842
Уязвимость сценариев активации конструктора виртуальной среды Python virtualenv, позволяющая нарушителю выполнить произвольные команды
Modified: 2025-02-10
CVE-2024-53899
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
Closed vulnerabilities
Modified: 2025-11-03
CVE-2024-47796
An improper array index validation vulnerability exists in the nowindow functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
- https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6
- https://talosintelligence.com/vulnerability_reports/TALOS-2024-2122
- https://lists.debian.org/debian-lts-announce/2025/01/msg00032.html
- https://lists.debian.org/debian-lts-announce/2025/06/msg00025.html
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2122
Modified: 2025-11-03
CVE-2024-52333
An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.