From 0fab7436a742d3f4e2260e183a9d563267fb75b8 Mon Sep 17 00:00:00 2001 From: GLSAMaker Date: Sun, 22 Sep 2024 06:59:11 +0000 Subject: [ GLSA 202409-12 ] pypy, pypy3: Multiple Vulnerabilities Bug: https://bugs.gentoo.org/741496 Bug: https://bugs.gentoo.org/741560 Bug: https://bugs.gentoo.org/774114 Bug: https://bugs.gentoo.org/782520 Signed-off-by: GLSAMaker Signed-off-by: Hans de Graaff --- glsa-202409-12.xml | 65 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 65 insertions(+) create mode 100644 glsa-202409-12.xml diff --git a/glsa-202409-12.xml b/glsa-202409-12.xml new file mode 100644 index 00000000..2eb42e1d --- /dev/null +++ b/glsa-202409-12.xml @@ -0,0 +1,65 @@ + + + + pypy, pypy3: Multiple Vulnerabilities + Multiple vulnerabilities have been discovered in pypy and pypy3, the worst of which could lead to arbitrary code execution. + pypy,pypy-exe,pypy-exe-bin,pypy3 + 2024-09-22 + 2024-09-22 + 741496 + 741560 + 774114 + 782520 + local + + + 7.3.3_p37_p1-r1 + 7.3.3_p37_p1-r1 + + + 7.3.2 + 7.3.2 + + + 7.3.2 + + + 7.3.3_p37_p1-r1 + 7.3.3_p37_p1-r1 + + + +

A fast, compliant alternative implementation of the Python language.

+
+ +

Multiple vulnerabilities have been discovered in pypy. Please review the CVE identifiers referenced below for details.

+
+ +

Please review the referenced CVE identifiers for details.

+
+ +

There is no known workaround at this time.

+
+ +

All pypy users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-python/pypy-7.3.3_p37_p1-r1" + # emerge --ask --oneshot --verbose ">=dev-python/pypy-exe-7.3.2" + # emerge --ask --oneshot --verbose ">=dev-python/pypy-exe-bin-7.3.2" + + +

All pypy3 users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=dev-python/pypy3-7.3.3_p37_p1-r1" + +
+ + CVE-2020-27619 + + graaff + graaff +
\ No newline at end of file -- cgit v1.2.3-65-gdbad