extraction filters (filter="data" and filter="tar")

to be bypassed using crafted symlinks and hard links.
      CVE-2025-4517 (bsc#1244032). Also addresses CVE-2025-4435
      (gh#135034, bsc#1244061).

OBS-URL: https://build.opensuse.org/package/show/devel:languages:python:Factory/python312?expand=0&rev=149
This commit is contained in:
2025-06-25 19:47:39 +00:00
committed by Git OBS Bridge
commit f9e1cf1836
42 changed files with 10795 additions and 0 deletions

View File

@@ -0,0 +1,13 @@
Index: Python-3.12.2/Lib/site.py
===================================================================
--- Python-3.12.2.orig/Lib/site.py
+++ Python-3.12.2/Lib/site.py
@@ -77,7 +77,7 @@ import io
import stat
# Prefixes for site-packages; add additional prefixes like /usr/local here
-PREFIXES = [sys.prefix, sys.exec_prefix]
+PREFIXES = [sys.prefix, sys.exec_prefix, '/usr/local']
# Enable per user site-packages directory
# set it to False to disable the feature or True to force the feature
ENABLE_USER_SITE = None