VYPR

rpm package

suse/python-base&distro=SUSE Linux Enterprise Module for Package Hub 15 SP7

pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Vulnerabilities (24)

  • CVE-2025-8291MedOct 7, 2025
    affected < 2.7.18-150000.86.1fixed 2.7.18-150000.86.1

    The 'zipfile' module would not check the validity of the ZIP64 End of Central Directory (EOCD) Locator record offset value would not be used to locate the ZIP64 EOCD record, instead the ZIP64 EOCD record would be assumed to be the previous record in the ZIP archive. This could be

  • CVE-2025-8194HigJul 28, 2025
    affected < 2.7.18-150000.83.1fixed 2.7.18-150000.83.1

    There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and deadlock during the parsing of maliciously cra

  • CVE-2025-6069MedJun 17, 2025
    affected < 2.7.18-150000.80.1fixed 2.7.18-150000.80.1

    The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

  • CVE-2024-7592Aug 19, 2024
    affected < 2.7.18-150000.105.1fixed 2.7.18-150000.105.1

    There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in

Page 2 of 2