OESA-2023-1004

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1004
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1004.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1004
Upstream
Published
2023-01-06T11:04:45Z
Modified
2025-08-12T05:15:04.991228Z
Summary
python-setuptools security update
Details

Setuptools is a collection of enhancements to the Python distutils that allow you to more easily build and distribute Python packages, especially ones that have dependencies on other packages.This package contains a python wheel of setuptools to use with venv.

Security Fix(es):

Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.(CVE-2022-40897)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / python-setuptools

Package

Name
python-setuptools
Purl
pkg:rpm/openEuler/python-setuptools&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
44.1.1-2.oe1

Ecosystem specific

{
    "src": [
        "python-setuptools-44.1.1-2.oe1.src.rpm"
    ],
    "noarch": [
        "python-setuptools-44.1.1-2.oe1.noarch.rpm",
        "python2-setuptools-44.1.1-2.oe1.noarch.rpm",
        "python-setuptools-help-44.1.1-2.oe1.noarch.rpm",
        "python3-setuptools-44.1.1-2.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / python-setuptools

Package

Name
python-setuptools
Purl
pkg:rpm/openEuler/python-setuptools&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
44.1.1-2.oe1

Ecosystem specific

{
    "src": [
        "python-setuptools-44.1.1-2.oe1.src.rpm"
    ],
    "noarch": [
        "python-setuptools-44.1.1-2.oe1.noarch.rpm",
        "python2-setuptools-44.1.1-2.oe1.noarch.rpm",
        "python-setuptools-help-44.1.1-2.oe1.noarch.rpm",
        "python3-setuptools-44.1.1-2.oe1.noarch.rpm"
    ]
}

openEuler:22.03-LTS / python-setuptools

Package

Name
python-setuptools
Purl
pkg:rpm/openEuler/python-setuptools&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
59.4.0-5.oe2203sp1

Ecosystem specific

{
    "src": [
        "python-setuptools-59.4.0-5.oe2203.src.rpm",
        "python-setuptools-59.4.0-5.oe2203sp1.src.rpm"
    ],
    "noarch": [
        "python3-setuptools-59.4.0-5.oe2203.noarch.rpm",
        "python-setuptools-59.4.0-5.oe2203.noarch.rpm",
        "python-setuptools-help-59.4.0-5.oe2203.noarch.rpm",
        "python3-setuptools-59.4.0-5.oe2203sp1.noarch.rpm",
        "python-setuptools-help-59.4.0-5.oe2203sp1.noarch.rpm",
        "python-setuptools-59.4.0-5.oe2203sp1.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / python-setuptools

Package

Name
python-setuptools
Purl
pkg:rpm/openEuler/python-setuptools&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
59.4.0-5.oe2203sp1

Ecosystem specific

{
    "src": [
        "python-setuptools-59.4.0-5.oe2203sp1.src.rpm"
    ],
    "noarch": [
        "python3-setuptools-59.4.0-5.oe2203sp1.noarch.rpm",
        "python-setuptools-help-59.4.0-5.oe2203sp1.noarch.rpm",
        "python-setuptools-59.4.0-5.oe2203sp1.noarch.rpm"
    ]
}