[CLSA-2026:1788336279] Fix CVE(s): CVE-2025-15367
Type:
security
Severity:
Important
Release date:
2026-09-02 08:04:50 UTC
Description:
* SECURITY UPDATE: control-character command injection in poplib - debian/patches/00475-CVE-2025-15367-poplib-reject-control-chars.patch: reject C0 control characters and DEL in POP3._putcmd() so a CR/LF in a user()/pass_() argument cannot inject a second POP3 command (CWE-77/CWE-93). - CVE-2025-15367
CVEs fixed:
Updated packages:
  • alt-python313_3.13.15-3_amd64.deb
    sha:12fee35a766a6003c5ce0669cd43c40bd4bbede4
  • alt-python313-debug_3.13.15-3_amd64.deb
    sha:875d6d024c932b7e38c0fc83b728d5f5a12b475c
  • alt-python313-devel_3.13.15-3_amd64.deb
    sha:d6d6bac2d195209f20b186649989cad6b4467768
  • alt-python313-idle_3.13.15-3_amd64.deb
    sha:581f786289421c28a9ca3eb8366f8220a3dbe21d
  • alt-python313-libs_3.13.15-3_amd64.deb
    sha:826e8dcbab9677ea7e94ab579a9a24aecc4e6ced
  • alt-python313-test_3.13.15-3_amd64.deb
    sha:d873226ec21ad486f9a333cd8bdee3fe93947db0
  • alt-python313-tkinter_3.13.15-3_amd64.deb
    sha:3d2d15b709738c3c9fbae697b3e0798e826ad95d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.