-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-8193 2013-05-15 02:36:51 --------------------------------------------------------------------------------
Name : python-virtualenv Product : Fedora 18 Version : 1.9.1 Release : 1.fc18 URL : http://pypi.python.org/pypi/virtualenv Summary : Tool to create isolated Python environments Description : virtualenv is a tool to create isolated Python environments. virtualenv is a successor to workingenv, and an extension of virtual-python. It is written by Ian Bicking, and sponsored by the Open Planning Project. It is licensed under an MIT-style permissive license. -------------------------------------------------------------------------------- Update Information: * Fixes two security issues with the bundled copy of pip: - Insecure tempdir usage CVE-2013-1888 - Uses http:// to download packages instead of https:// See changelog at: http://pypi.python.org/pypi/virtualenv#id2 Multiple bugfixes. See http://pypi.python.org/pypi/virtualenv/1.7.1.2 for information. Multiple bugfixes. See http://pypi.python.org/pypi/virtualenv/1.7.1.2 for information. See changelog at: http://pypi.python.org/pypi/virtualenv#id2 Multiple bugfixes. See http://pypi.python.org/pypi/virtualenv/1.7.1.2 for information. Multiple bugfixes. See http://pypi.python.org/pypi/virtualenv/1.7.1.2 for information. See changelog at: http://pypi.python.org/pypi/virtualenv#id2 Multiple bugfixes. See http://pypi.python.org/pypi/virtualenv/1.7.1.2 for information. Multiple bugfixes. See http://pypi.python.org/pypi/virtualenv/1.7.1.2 for information. -------------------------------------------------------------------------------- ChangeLog: * Tue May 14 2013 Toshio Kuratomi <[email protected]> - 1.9.1-1 - Update to upstream 1.9.1 because of security issues with the bundled python-pip in older releases. This is just a quick fix until a python-virtualenv maintainer can unbundle the python-pip package see: https://bugzilla.redhat.com/show_bug.cgi?id=749378 * Thu Feb 14 2013 Fedora Release Engineering <[email protected]> - 1.7.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #923974 - CVE-2013-1888 python-pip: insecure temporary directory usage https://bugzilla.redhat.com/show_bug.cgi?id=923974 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python-virtualenv' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list [email protected] https://admin.fedoraproject.org/mailman/listinfo/package-announce
