VDB
BDU%3A2025-12377
BDU%3A2025-12377
PUBLISHED
CVSS 5 MEDIUM
Уязвимость интерпретатора языка программирования Python, связанная с неправильным ограничением пути к ограниченному каталогу, позволяющая нарушителю получить доступ на изменение произвольных файлы в системе
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Canonical Ltd., Fedora Project, Python Software Foundation, АО "НППКТ", ООО «НЦПР» | SUSE Linux Enterprise High Performance Computing, Red Hat Enterprise Linux, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Module for Desktop Applications, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise Micro, SUSE Manager Retail Branch Server, SUSE Manager Proxy, SUSE Manager Server, SUSE Linux Enterprise Module for Public Cloud, SUSE Linux Enterprise Module for Package Hub, Suse Linux Enterprise Desktop, Ubuntu, OpenSUSE Leap, SUSE Linux Enterprise Module for Development Tools, SUSE Linux Enterprise Module for Python 3, SUSE Linux Enterprise Module for Legacy, Fedora, SUSE Linux Micro, Python, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), МСВСфера |
Timeline
- Sep 29, 2025 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://github.com/python/cpython/issues/135034 url
- https://github.com/python/cpython/pull/135037 url
- https://redos.red-soft.ru/support/secure/ url
- https://access.redhat.com/security/cve/cve-2024-12718 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2023-9d033517d4 url
- https://github.com/python/cpython/issues/127987 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory
- https://ubuntu.com/security/CVE-2024-12718 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2024-82a696ca59 advisory
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-41dc96c19a advisory
- https://security-tracker.debian.org/tracker/CVE-2024-12718 url
- https://bodhi.fedoraproject.org/updates/FEDORA-2025-3436f3d2b4 url
- https://www.suse.com/security/cve/CVE-2024-12718.html url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.14/ url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:10136?lang=ru advisory