[ubuntu/noble-updates] python-pip 24.0+dfsg-1ubuntu1.3 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Tue Sep 23 14:58:34 UTC 2025


python-pip (24.0+dfsg-1ubuntu1.3) noble-security; urgency=medium

  * SECURITY UPDATE: http body leakage via http redirect
    - debian/patches/CVE-2023-45803.patch: removes the body from the
      http request when it is redirected to a different origin and the
      http verb is changed to GET.
    - CVE-2023-45803
  * SECURITY UPDATE: resource exhaustion
    - debian/patches/CVE-2024-3651.patch: checks input before processing
    - CVE-2024-3651
  * SECURITY UPDATE: Information Leak
    - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
      lookup instead of netloc
    - CVE-2024-47081

Date: 2025-09-22 20:15:13.652713+00:00
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/python-pip/24.0+dfsg-1ubuntu1.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list