--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2022-0d007466b3
2022-03-26 14:56:28.653571
--------------------------------------------------------------------------------
Name : pipenv
Product : Fedora 36
Version : 2021.5.29
Release : 7.fc36
URL :
https://github.com/pypa/pipenv
Summary : The higher level Python packaging tool
Description :
The Python packaging tool that aims to bring
the best of all packaging worlds (bundler, composer, npm, cargo, yarn, etc.)
to the Python world. It automatically creates and manages a virtualenv for
your projects, as well as adds/removes packages from your Pipfile as you
install/uninstall packages. It also generates the ever���important Pipfile.lock,
which is used to produce deterministic builds.
--------------------------------------------------------------------------------
Update Information:
Fix for CVE-2022-21668 for pipenv: code execution via crafted requirements.txt
file
--------------------------------------------------------------------------------
ChangeLog:
* Thu Feb 24 2022 Tomas Orsava <torsava(a)redhat.com> - 2021.5.29-7
- Fix for CVE-2022-21668
Resolves: rhbz#2039830
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #2039831 - CVE-2022-21668 pipenv: code execution via crafted requirements.txt
file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=2039831
--------------------------------------------------------------------------------
This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2022-0d007466b3' at the command
line. For more information, refer to the dnf documentation available at
http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------