[Bug 298351] devel/py-setuptools: CVE-2025-47273 remains flagged in 63.1.0_3; request update or security backport Port: devel/py-setuptools Installed package: py312-setuptools-63.1.0_3 System: FreeBSD 15, amd64 Ports branch: main `pkg audit` reports that py
- In reply to: bugzilla-noreply_a_freebsd.org: "[Bug 298351] devel/py-setuptools: CVE-2025-47273 remains flagged in 63.1.0_3; request update or security backport Port: devel/py-setuptools Installed package: py312-setuptools-63.1.0_3 System: FreeBSD 15, amd64 Ports branch: main `pkg audit` reports that py"
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Thu, 10 Sep 2026 17:28:02 UTC
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=298351
Charlie Li <vishwin@freebsd.org> changed:
What |Removed |Added
----------------------------------------------------------------------------
Resolution|--- |Not Accepted
CC| |vishwin@freebsd.org
Status|New |Closed
Flags|maintainer-feedback?(python |maintainer-feedback+
|@FreeBSD.org) |
--- Comment #1 from Charlie Li <vishwin@freebsd.org> ---
This is not exploitable on FreeBSD Ports with our package.
The functionality concerns downloading assets for packages, which has been
deprecated for a long time now. This code path is only taken when setuptools
itself is used for installing packages into a site-packages, usually with
easy_install, which we do not include in our package. In a pure Python
environment, this functionality is supplanted by pip. The Ports environment has
never used this downloading-assets part of the (deprecated) package management
functionality.
--
You are receiving this mail because:
You are the assignee for the bug.