[ubuntu/questing-proposed] python-pip 25.1.1+dfsg-1ubuntu2 (Accepted)

Hlib Korzhynskyy hlib.korzhynskyy at canonical.com
Mon Sep 22 20:40:48 UTC 2025


python-pip (25.1.1+dfsg-1ubuntu2) questing; urgency=medium

  * SECURITY UPDATE: Information Leak
    - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
      lookup instead of netloc
    - CVE-2024-47081

Date: Mon, 22 Sep 2025 17:45:42 -0230
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/python-pip/25.1.1+dfsg-1ubuntu2
-------------- next part --------------
Format: 1.8
Date: Mon, 22 Sep 2025 17:45:42 -0230
Source: python-pip
Built-For-Profiles: noudeb
Architecture: source
Version: 25.1.1+dfsg-1ubuntu2
Distribution: questing
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
Changes:
 python-pip (25.1.1+dfsg-1ubuntu2) questing; urgency=medium
 .
   * SECURITY UPDATE: Information Leak
     - debian/patches/CVE-2024-47081.patch: Only use hostname to do netrc
       lookup instead of netloc
     - CVE-2024-47081
Checksums-Sha1:
 9d30c11e4e7d1ba74a4b1b13ca2441cb845a5871 2568 python-pip_25.1.1+dfsg-1ubuntu2.dsc
 7a0a701e5d8d62ca4b12bce915064ad3d679f638 23544 python-pip_25.1.1+dfsg-1ubuntu2.debian.tar.xz
 c7a955e60291443e7c733e4e60d9478b82013eff 9010 python-pip_25.1.1+dfsg-1ubuntu2_source.buildinfo
Checksums-Sha256:
 e87e00a540689f42c9c8f02aa880babc135c6356c836764bd44efb0cbe009b6b 2568 python-pip_25.1.1+dfsg-1ubuntu2.dsc
 a187013c5fed746e0423633158085ccbbb8e7ade54c2af04964eadb14fd003e8 23544 python-pip_25.1.1+dfsg-1ubuntu2.debian.tar.xz
 5c5b3aa12ebeb374ba801097b8021ef1169e7cd84f70198d3f832047afbb9e3d 9010 python-pip_25.1.1+dfsg-1ubuntu2_source.buildinfo
Files:
 4663727322ec7f3137877d5ae7f9b50a 2568 python optional python-pip_25.1.1+dfsg-1ubuntu2.dsc
 be49e50eb59551aa9f1cd2b8264ebdcc 23544 python optional python-pip_25.1.1+dfsg-1ubuntu2.debian.tar.xz
 0e67bed4470a524178fab3d6e0e8b8d5 9010 python optional python-pip_25.1.1+dfsg-1ubuntu2_source.buildinfo
Original-Maintainer: Debian Python Team <team+python at tracker.debian.org>


More information about the Questing-changes mailing list