安全公告详情

NS-SA-2025-0209

2025-09-30 16:49:52

简介

moderate: python-pip/p11-kit security update

严重级别

moderate

主题

An update for python-pip/p11-kit is now available for NewStart CGSL MAIN 6.06.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

python-pip:
p11-kit:


Security Fix(es):
python-pip: pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.(CVE-2013-1888)
python-pip: bugfix
p11-kit: An issue was discovered in p11-kit 0.21.1 through 0.23.21. Multiple integer overflows have been discovered in the array allocations in the p11-kit library and the p11-kit list command, where overflow checks are missing before calling realloc or calloc.(CVE-2020-29361)
p11-kit: An issue was discovered in p11-kit 0.21.1 through 0.23.21. A heap-based buffer over-read has been discovered in the RPC protocol used by thep11-kit server/remote commands and the client library. When the remote entity supplies a byte array through a serialized PKCS#11 function call, the receiving entity may allow the reading of up to 4 bytes of memory past the heap allocation.(CVE-2020-29362)
p11-kit: An issue was discovered in p11-kit 0.23.6 through 0.23.21. A heap-based buffer overflow has been discovered in the RPC protocol used by p11-kit server/remote commands and the client library. When the remote entity supplies a serialized byte array in a CK_ATTRIBUTE, the receiving entity may not allocate sufficient length for the buffer to store the deserialized value.(CVE-2020-29363)
p11-kit: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.06.01B6.

影响组件

  • python-pip
  • p11-kit

影响产品

  • CGSL MAIN 6.06

更新包

{"fix":[{"product":"CGSL MAIN 6.06","pkgs":[{"binary":["platform-python-pip-9.0.3-22.zncgsl6.noarch.rpm","python3-pip-9.0.3-22.zncgsl6.noarch.rpm","python3-pip-wheel-9.0.3-22.zncgsl6.noarch.rpm"],"source":"python-pip-9.0.3-22.zncgsl6.src.rpm"},{"binary":["p11-kit-0.23.22-1.zncgsl6.x86_64.rpm","p11-kit-trust-0.23.22-1.zncgsl6.x86_64.rpm"],"source":"p11-kit-0.23.22-1.zncgsl6.src.rpm"}]}]}

CVE

参考