ELA-452-1 python-pip security update

remote code execution

2021-07-03
Packagepython-pip
Version1.5.6-5+deb8u2
Related CVEs CVE-2021-3572


It was discovered that pip incorrectly handled unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository.



For Debian 8 jessie, these problems have been fixed in version 1.5.6-5+deb8u2.

We recommend that you upgrade your python-pip packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.