--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-77ce20f03a
2022-03-11 14:43:31.710749
--------------------------------------------------------------------------------
Name : pipenv
Product : Fedora 35
Version : 2021.5.29
Release : 7.fc35
URL :
https://github.com/pypa/pipenv
Summary : The higher level Python packaging tool
Description :
The Python packaging tool that aims to bring
the best of all packaging worlds (bundler, composer, npm, cargo, yarn, etc.)
to the Python world. It automatically creates and manages a virtualenv for
your projects, as well as adds/removes packages from your Pipfile as you
install/uninstall packages. It also generates the ever���important Pipfile.lock,
which is used to produce deterministic builds.
--------------------------------------------------------------------------------
Update Information:
Fix for CVE-2022-21668 for pipenv: code execution via crafted requirements.txt
file
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 24 2022 Tomas Orsava <torsava(a)redhat.com> - 2021.5.29-7
- Fix for CVE-2022-21668
Resolves: rhbz#2039830
* Fri Jan 21 2022 Fedora Release Engineering <releng(a)fedoraproject.org> -
2021.5.29-6
- Rebuilt for
https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Thu Dec 2 2021 Charalampos Stratakis <cstratak(a)redhat.com> - 2021.5.29-5
- Remove bundled windows executables
Resolves: rhbz#2005460
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2039831 - CVE-2022-21668 pipenv: code execution via crafted requirements.txt
file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2039831
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-77ce20f03a' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------