OESA-2023-1904

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1904
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1904.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2023-1904
Upstream
Published
2023-12-15T11:06:27Z
Modified
2025-09-03T06:18:27.926928Z
Summary
python-wheel security update
Details

A built-package format for Python. A wheel is a ZIP-format archive with a specially formatted filename and the .whl extension. It is designed to contain all the files for a PEP 376 compatible install in a way that is very close to the on-disk format.

Security Fix(es):

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.(CVE-2022-40898)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / python-wheel

Package

Name
python-wheel
Purl
pkg:rpm/openEuler/python-wheel&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.31.1-6.oe1

Ecosystem specific

{
    "src": [
        "python-wheel-0.31.1-6.oe1.src.rpm"
    ],
    "noarch": [
        "python3-wheel-0.31.1-6.oe1.noarch.rpm",
        "python-wheel-wheel-0.31.1-6.oe1.noarch.rpm",
        "python2-wheel-0.31.1-6.oe1.noarch.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / python-wheel

Package

Name
python-wheel
Purl
pkg:rpm/openEuler/python-wheel&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.31.1-6.oe1

Ecosystem specific

{
    "src": [
        "python-wheel-0.31.1-6.oe1.src.rpm"
    ],
    "noarch": [
        "python2-wheel-0.31.1-6.oe1.noarch.rpm",
        "python3-wheel-0.31.1-6.oe1.noarch.rpm",
        "python-wheel-wheel-0.31.1-6.oe1.noarch.rpm"
    ]
}

openEuler:22.03-LTS / python-wheel

Package

Name
python-wheel
Purl
pkg:rpm/openEuler/python-wheel&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.37.0-6.oe2203sp2

Ecosystem specific

{
    "src": [
        "python-wheel-0.37.0-6.oe2203.src.rpm",
        "python-wheel-0.37.0-6.oe2203sp1.src.rpm",
        "python-wheel-0.37.0-6.oe2203sp2.src.rpm"
    ],
    "noarch": [
        "python3-wheel-0.37.0-6.oe2203.noarch.rpm",
        "python-wheel-wheel-0.37.0-6.oe2203.noarch.rpm",
        "python-wheel-wheel-0.37.0-6.oe2203sp1.noarch.rpm",
        "python3-wheel-0.37.0-6.oe2203sp1.noarch.rpm",
        "python3-wheel-0.37.0-6.oe2203sp2.noarch.rpm",
        "python-wheel-wheel-0.37.0-6.oe2203sp2.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / python-wheel

Package

Name
python-wheel
Purl
pkg:rpm/openEuler/python-wheel&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.37.0-6.oe2203sp1

Ecosystem specific

{
    "src": [
        "python-wheel-0.37.0-6.oe2203sp1.src.rpm"
    ],
    "noarch": [
        "python-wheel-wheel-0.37.0-6.oe2203sp1.noarch.rpm",
        "python3-wheel-0.37.0-6.oe2203sp1.noarch.rpm"
    ]
}

openEuler:22.03-LTS-SP2 / python-wheel

Package

Name
python-wheel
Purl
pkg:rpm/openEuler/python-wheel&distro=openEuler-22.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.37.0-6.oe2203sp2

Ecosystem specific

{
    "src": [
        "python-wheel-0.37.0-6.oe2203sp2.src.rpm"
    ],
    "noarch": [
        "python3-wheel-0.37.0-6.oe2203sp2.noarch.rpm",
        "python-wheel-wheel-0.37.0-6.oe2203sp2.noarch.rpm"
    ]
}