From 6d9bab7165f0e1c5bfd02a22872a3fcd19842aa9 Mon Sep 17 00:00:00 2001 From: STX Builder Date: Fri, 6 Sep 2024 08:58:48 +0000 Subject: [PATCH] Debian: setuptools: fix CVE-2022-40897/CVE-2024-6345 Upgrade setuptools to 52.0.0-4+deb11u1 Refer to: https://nvd.nist.gov/vuln/detail/CVE-2022-40897 https://nvd.nist.gov/vuln/detail/CVE-2024-6345 Test Plan: Pass: downloader Pass: build-pkgs --clean --all Pass: build-image Pass: boot Closes-bug: #2079771 Change-Id: I9ad07b3a4af23c77791bba6c6f03ce187eba4443 Signed-off-by: Wentao Zhang --- python/python3-setuptools/debian/meta_data.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/python/python3-setuptools/debian/meta_data.yaml b/python/python3-setuptools/debian/meta_data.yaml index 60af33817..cc5cd6452 100644 --- a/python/python3-setuptools/debian/meta_data.yaml +++ b/python/python3-setuptools/debian/meta_data.yaml @@ -1,7 +1,7 @@ --- debname: setuptools -debver: 52.0.0-4 -archive: https://snapshot.debian.org/archive/debian/20210629T151153Z/pool/main/s/setuptools/ +debver: 52.0.0-4+deb11u1 +archive: https://snapshot.debian.org/archive/debian-security/20240904T224638Z/pool/updates/main/s/setuptools/ revision: dist: $STX_DIST PKG_GITREVCOUNT: true