-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2022-77ce20f03a 2022-03-11 14:43:31.710749 --------------------------------------------------------------------------------
Name : pipenv Product : Fedora 35 Version : 2021.5.29 Release : 7.fc35 URL : https://github.com/pypa/pipenv Summary : The higher level Python packaging tool Description : The Python packaging tool that aims to bring the best of all packaging worlds (bundler, composer, npm, cargo, yarn, etc.) to the Python world. It automatically creates and manages a virtualenv for your projects, as well as adds/removes packages from your Pipfile as you install/uninstall packages. It also generates the ever���important Pipfile.lock, which is used to produce deterministic builds.
-------------------------------------------------------------------------------- Update Information:
Fix for CVE-2022-21668 for pipenv: code execution via crafted requirements.txt file -------------------------------------------------------------------------------- ChangeLog:
* Thu Feb 24 2022 Tomas Orsava torsava@redhat.com - 2021.5.29-7 - Fix for CVE-2022-21668 Resolves: rhbz#2039830 * Fri Jan 21 2022 Fedora Release Engineering releng@fedoraproject.org - 2021.5.29-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Thu Dec 2 2021 Charalampos Stratakis cstratak@redhat.com - 2021.5.29-5 - Remove bundled windows executables Resolves: rhbz#2005460 -------------------------------------------------------------------------------- References:
[ 1 ] Bug #2039831 - CVE-2022-21668 pipenv: code execution via crafted requirements.txt file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2039831 --------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-77ce20f03a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys --------------------------------------------------------------------------------