ALT-BU-2026-1016-1
Branch c10f2 update bulletin.
Package python3-module-virtualenv updated to version 20.26.6-alt0.c10f2.1 for branch c10f2 in task 403775.
Closed vulnerabilities
Modified: 2025-08-13
BDU:2024-10842
Уязвимость сценариев активации конструктора виртуальной среды Python virtualenv, позволяющая нарушителю выполнить произвольные команды
Modified: 2025-02-10
CVE-2024-53899
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
Package python-module-future updated to version 0.18.2-alt1.c10f2.1 for branch c10f2 in task 404152.
Closed vulnerabilities
Modified: 2025-10-02
BDU:2023-02446
Уязвимость программы совместимости версий Python Charmers Future, связанная с некорректным регулярным выражением, позволяющая нарушителю вызывать отказ в обслуживании
Modified: 2025-04-15
CVE-2022-40899
An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
- https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215
- https://github.com/PythonCharmers/python-future/pull/610
- https://github.com/python/cpython/pull/17157
- https://pypi.org/project/future/
- https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
- https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215
- https://github.com/PythonCharmers/python-future/pull/610
- https://github.com/python/cpython/pull/17157
- https://pypi.org/project/future/
- https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/