ALAS-2025-831


Amazon Linux 2023 Security Advisory: ALAS-2025-831
Advisory Release Date: 2025-01-30 03:53 Pacific
Advisory Updated Date: 2025-02-05 11:08 Pacific
Severity: Important

Issue Overview:

virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287. (CVE-2024-53899)


Affected Packages:

python-virtualenv


Issue Correction:
Run dnf update python-virtualenv --releasever 2023.6.20250203 to update your system.

New Packages:
noarch:
    python3-virtualenv-20.4.0-3.amzn2023.0.4.noarch

src:
    python-virtualenv-20.4.0-3.amzn2023.0.4.src