Critical Security Advisory for Fedora 39: python-astropy CVE-2023-41334 Update
Summary
The Astropy project is a common effort to develop a single core package
for Astronomy. Major packages such as PyFITS, PyWCS, vo, and asciitable
already merged in, and many more components being worked on. In
particular, we are developing imaging, photometric, and spectroscopic
functionality, as well as frameworks for cosmology, unit handling, and
coordinate transformations.
Update Information:
Security fix for CVE-2023-41334
Change Log
* Wed Jun 26 2024 Sergio Pascual
References
[ 1 ] Bug #2270185 - CVE-2023-41334 python-astropy: Remote code execution in TranformGraph().to_dot_graph function
https://bugzilla.redhat.com/show_bug.cgi?id=2270185
Update Instructions
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-d8ac19de55' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label